Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
48,364 matching · page 379/968Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-17574(opens NVD record) | Medium | 5.5 | HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read. | Jul 27, 2026 |
| CVE-2026-17573(opens NVD record) | Medium | 5.5 | A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free. | Jul 27, 2026 |
| CVE-2026-17572(opens NVD record) | Medium | 5.5 | Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum. | Jul 27, 2026 |
| CVE-2026-17530(opens NVD record) | Medium | 6.3 | A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue. | Jul 27, 2026 |
| CVE-2026-17529(opens NVD record) | Medium | 6.3 | A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue. | Jul 27, 2026 |
| CVE-2026-16812(opens NVD record) | Critical | 10.0 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited. | Jul 27, 2026 |
| CVE-2025-50455(opens NVD record) | Critical | 9.1 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE. | Jul 27, 2026 |
| CVE-2026-66477(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in Gillion <= 4.13 versions. | Jul 27, 2026 |
| CVE-2026-66476(opens NVD record) | Medium | 4.9 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | Jul 27, 2026 |
| CVE-2026-66475(opens NVD record) | Medium | 5.9 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | Jul 27, 2026 |
| CVE-2026-66474(opens NVD record) | Medium | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. | Jul 27, 2026 |
| CVE-2026-66448(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | Jul 27, 2026 |
| CVE-2026-66445(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | Jul 27, 2026 |
| CVE-2026-66442(opens NVD record) | Medium | 5.4 | Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. | Jul 27, 2026 |
| CVE-2026-66438(opens NVD record) | Medium | 5.3 | Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions. | Jul 27, 2026 |
| CVE-2026-66437(opens NVD record) | Medium | 4.9 | Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | Jul 27, 2026 |
| CVE-2026-66434(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | Jul 27, 2026 |
| CVE-2026-66433(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | Jul 27, 2026 |
| CVE-2026-66428(opens NVD record) | Medium | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | Jul 27, 2026 |
| CVE-2026-66427(opens NVD record) | High | 7.6 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | Jul 27, 2026 |
| CVE-2026-66050(opens NVD record) | High | 7.5 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login. | Jul 27, 2026 |
| CVE-2026-65568(opens NVD record) | Medium | 5.0 | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | Jul 27, 2026 |
| CVE-2026-65567(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | Jul 27, 2026 |
| CVE-2026-65564(opens NVD record) | Medium | 5.3 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | Jul 27, 2026 |
| CVE-2026-65563(opens NVD record) | Medium | 5.9 | Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | Jul 27, 2026 |
| CVE-2026-65562(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | Jul 27, 2026 |
| CVE-2026-65561(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | Jul 27, 2026 |
| CVE-2026-65558(opens NVD record) | Medium | 5.4 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | Jul 27, 2026 |
| CVE-2026-65557(opens NVD record) | Medium | 5.9 | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | Jul 27, 2026 |
| CVE-2026-65436(opens NVD record) | Medium | 6.8 | Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. | Jul 27, 2026 |
| CVE-2026-65435(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | Jul 27, 2026 |
| CVE-2026-65434(opens NVD record) | Medium | 6.5 | Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions. | Jul 27, 2026 |
| CVE-2026-65433(opens NVD record) | Medium | 6.5 | Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | Jul 27, 2026 |
| CVE-2026-59560(opens NVD record) | Medium | 6.5 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | Jul 27, 2026 |
| CVE-2026-59559(opens NVD record) | Medium | 6.5 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | Jul 27, 2026 |
| CVE-2026-59558(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | Jul 27, 2026 |
| CVE-2026-59557(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | Jul 27, 2026 |
| CVE-2026-59556(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | Jul 27, 2026 |
| CVE-2026-59553(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | Jul 27, 2026 |
| CVE-2026-59552(opens NVD record) | High | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | Jul 27, 2026 |
| CVE-2026-59551(opens NVD record) | High | 8.5 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Jul 27, 2026 |
| CVE-2026-59550(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | Jul 27, 2026 |
| CVE-2026-59549(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Jul 27, 2026 |
| CVE-2026-59548(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | Jul 27, 2026 |
| CVE-2026-59546(opens NVD record) | High | 7.4 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | Jul 27, 2026 |
| CVE-2026-59539(opens NVD record) | High | 7.5 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | Jul 27, 2026 |
| CVE-2026-59538(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | Jul 27, 2026 |
| CVE-2026-59537(opens NVD record) | High | 7.6 | Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | Jul 27, 2026 |
| CVE-2026-59536(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | Jul 27, 2026 |
| CVE-2026-59535(opens NVD record) | High | 7.3 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | Jul 27, 2026 |