Export limit exceeded: 404435 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404435 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94676 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.
CVE-2026-94666 2026-10-11 7.5 High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1.
CVE-2026-94590 2026-10-11 6.5 Medium
Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.
CVE-2026-94421 2026-10-11 6.4 Medium
The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-94065 2026-10-11 8.8 High
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.
CVE-2026-94064 2026-10-11 8.8 High
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
CVE-2026-93950 2026-10-11 7.5 High
Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
CVE-2026-93949 2026-10-11 7.1 High
Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3.
CVE-2026-93945 2 Axiomthemes, Wordpress-extensions 2 Balance, Balance 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
CVE-2026-93944 2 Themerex Group, Wordpress-extensions 2 Camelia, Camelia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
CVE-2026-93943 2 Themerex Group, Wordpress-extensions 2 Convex, Convex 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
CVE-2026-93942 2 Themerex Group, Wordpress-extensions 2 Dwell, Dwell 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
CVE-2026-93941 2 Themerex Group, Wordpress-extensions 2 Edema, Edema 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
CVE-2026-93940 2 Themerex Group, Wordpress-extensions 2 Greeny, Greeny 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
CVE-2026-93938 2 Themerex Group, Wordpress-extensions 2 Hogwords, Hogwords 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
CVE-2026-93937 2 Themerex Group, Wordpress-extensions 2 Hygia, Hygia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
CVE-2026-93936 2 Themerex Group, Wordpress-extensions 2 Ipharm, Ipharm 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
CVE-2026-93935 2 Themerex Group, Wordpress-extensions 2 Let's Play, Let's Play 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
CVE-2026-93934 2 Themerex Group, Wordpress-extensions 2 Partiso, Partiso 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
CVE-2026-93933 2 Themerex Group, Wordpress-extensions 2 Rosalinda, Rosalinda 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.