21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 3101-3150 of 21637 CVEs Page 63 of 433
CVE-2026-57818
Analyzed
8.1
Apache Apache CXF

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting...

2026-08-06
CVE-2026-57817
Analyzed
9.8
Apache Apache CXF

Apache CXF fails to validate the c_hash parameter in OpenID Connect Hybrid Flow, allowing for Authorization Code Substitution or Injection attacks whe...

2026-08-06
CVE-2026-57813
Analyzed
9.8
WordPress MailOptin

The MailOptin plugin for WordPress contains an incorrect privilege assignment vulnerability, allowing unauthenticated attackers to escalate their priv...

2026-07-14
CVE-2026-57811
Analyzed
10
WordPress Realtyna Organic IDX plugin

The Realtyna Organic IDX plugin for WordPress contains a Code Injection vulnerability, allowing unauthenticated remote code execution.

2026-07-14
CVE-2026-57810
Analyzed
8.5
WordPress APIExperts Square for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woo...

2026-07-14
CVE-2026-5781
Analyzed
8.8
MphRx Multiple Products

An authorization vulnerability in MphRx's Minerva V3

2026-05-29
CVE-2026-57807
Analyzed
9.8
WordPress OAuth Single Sign On - SSO (OAuth Client)

An authentication bypass vulnerability in the miniOrange OAuth Single Sign On plugin allows unauthorized attackers to exploit password recovery mechan...

2026-07-11
CVE-2026-57803
Analyzed
7.5
HP Struktur Core

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core s...

2026-07-14
CVE-2026-57802
Analyzed
7.5
HP Struktur

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur strukt...

2026-07-14
CVE-2026-57801
Analyzed
7.5
HP SetSail

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail...

2026-07-14
CVE-2026-57800
Analyzed
7.5
HP Overworld

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overwor...

2026-07-14
CVE-2026-57799
Analyzed
7.5
HP Nuss

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Lo...

2026-07-14
CVE-2026-57798
Analyzed
7.5
HP NewsPlus Shortcodes

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortc...

2026-07-14
CVE-2026-57796
Analyzed
7.5
HP Leedo

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows P...

2026-07-14
CVE-2026-57795
Analyzed
7.5
HP Kitchor

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor al...

2026-07-14
CVE-2026-57794
Analyzed
7.5
HP Golo Framework

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-fra...

2026-07-14
CVE-2026-57793
Analyzed
7.5
HP Flow

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allow...

2026-07-14
CVE-2026-57792
Analyzed
7.5
HP Dør

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows...

2026-07-14
CVE-2026-57791
Analyzed
7.5
HP Brook

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows...

2026-07-14
CVE-2026-57790
Analyzed
7.5
HP Billey

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allow...

2026-07-14
CVE-2026-57789
Analyzed
7.5
HP Aqua

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PH...

2026-07-14
CVE-2026-57788
Analyzed
7.5
HP Aalto

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allow...

2026-07-14
CVE-2026-57787
Analyzed
8.5
WordPress CWS SVGicons

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blin...

2026-07-14
CVE-2026-57786
Analyzed
8.8
WordPress WorkScout-Core

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass

2026-07-14
CVE-2026-57785
Analyzed
8.8
WordPress ApusListing

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1

2026-07-24
CVE-2026-57784
Analyzed
9.6
WordPress Ninja Forms File Uploads Extension

The Ninja Forms File Uploads Extension for WordPress contains a Cross Site Request Forgery (CSRF) vulnerability that may allow an attacker to perform...

2026-07-24
CVE-2026-57773
Analyzed
7.6
Zorem Advanced Advanced Shipment Tracking for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce...

2026-07-14
CVE-2026-57772
Analyzed
8.5
Intel WP Inventory Manager

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-m...

2026-07-14
CVE-2026-57771
Analyzed
8.5
WordPress GD Rating System

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system...

2026-07-14
CVE-2026-57770
Analyzed
9.8
HP Grand Photography

ThemeGoods Grand Photography is vulnerable to PHP Object Injection due to improper deserialization of untrusted data, allowing unauthenticated attacke...

2026-07-14
CVE-2026-57768
Analyzed
8.2
WordPress Houzez Login Register

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation

2026-07-14
CVE-2026-57766
Analyzed
8.8
WordPress File Manager & Code Editor

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3

2026-07-03
CVE-2026-57765
Analyzed
8.5
Levelfourdevelopment WP EasyCart

Contributor SQL Injection in WP EasyCart <= 5

2026-07-03
CVE-2026-57759
Analyzed
8.8
Metagauss ProfileGrid

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5

2026-07-03
CVE-2026-57756
Analyzed
8.5
Unknown nicen-localize-image

Contributor SQL Injection in nicen-localize-image <= 1

2026-07-03
CVE-2026-57752
Analyzed
8.5
Unknown iNET Webkit

Contributor SQL Injection in iNET Webkit 1

2026-07-03
CVE-2026-57751
Analyzed
8.1
Heateor Heateor Social Login

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1

2026-07-03
CVE-2026-57744
Analyzed
9.8
HP RT-Theme 18 | Extensions

A deserialization of untrusted data vulnerability in the stmcan RT-Theme 18 | Extensions WordPress plugin allows for PHP object injection.

2026-07-14
CVE-2026-57743
Analyzed
8.1
HP RT-Theme 18 | Extensions

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensio...

2026-07-14
CVE-2026-57739
Analyzed
9.3
WordPress AcyMailing SMTP Newsletter

The AcyMailing SMTP Newsletter plugin for WordPress contains a Blind SQL Injection vulnerability allowing unauthenticated attackers to extract databas...

2026-07-14
CVE-2026-57738
Analyzed
9.8
HP 777

A deserialization of untrusted data vulnerability in the axiomthemes 777 WordPress theme allows for PHP object injection.

2026-07-14
CVE-2026-57729
Analyzed
7.5
UX-themes Flatsome

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels

2026-07-14
CVE-2026-57727
Analyzed
7.5
Themeum Kirki

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels

2026-07-14
CVE-2026-57726
Analyzed
9.3
WordPress Kirki

Themeum Kirki is susceptible to a Blind SQL Injection vulnerability, allowing unauthenticated attackers to manipulate SQL queries.

2026-07-14
CVE-2026-57724
Analyzed
9.8
HP Kirki

A deserialization of untrusted data vulnerability in the Themeum Kirki WordPress plugin allows for PHP object injection.

2026-07-14
CVE-2026-57719
Analyzed
10
WordPress Aimogen Pro

CodeRevolution Aimogen Pro for WordPress is vulnerable to an unrestricted file upload flaw, allowing unauthenticated attackers to upload malicious fil...

2026-07-14
CVE-2026-57714
Analyzed
9.3
WordPress LatePoint

The LatePoint WordPress plugin is susceptible to Blind SQL Injection, enabling unauthenticated remote attackers to execute malicious database queries.

2026-07-14
CVE-2026-57713
Analyzed
8.8
HP Events Manager

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection

2026-07-14
CVE-2026-57710
Analyzed
9.9
Unknown WoowBot Pro Max

An unrestricted file upload vulnerability in the quantumcloud WoowBot Pro Max plugin allows authenticated attackers to upload malicious files, potenti...

2026-07-14
CVE-2026-57709
Analyzed
8.6
WP Swings Membership For WooCommerce

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-wo...

2026-07-14