Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-5778

Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing a large out-of-bounds read and crash. An unauthenticated attacker can trigger this remotely via malformed TLS Application Data records.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
LOW
Conflicts
0

CVE-2026-57779

Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.

PUBLISHED
Vendor
themebeez
Product
Fascinate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57778

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

PUBLISHED
Vendor
wpdevart
Product
Booking calendar, Appointment Booking System
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57776

Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.

PUBLISHED
Vendor
vowelweb
Product
VW Wedding
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57774

Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.

PUBLISHED
Vendor
vowelweb
Product
VW Food Corner
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57773

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.

PUBLISHED
Vendor
Zorem
Product
Advanced Shipment Tracking for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-57772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.

PUBLISHED
Vendor
WP Inventory
Product
WP Inventory Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-57771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.

PUBLISHED
Vendor
Milan Petrovic
Product
GD Rating System
Provider severity
HIGH
Conflicts
0

CVE-2026-57770

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Photography
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5777

This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete compromise of the targeted device.

PUBLISHED
Vendor
EGate
Product
Atom 3X Projector
Provider severity
HIGH
Conflicts
0

CVE-2026-57769

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Photography
Provider severity
HIGH
Conflicts
0

CVE-2026-57768

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

PUBLISHED
Vendor
favethemes
Product
Houzez Login Register
Provider severity
HIGH
Conflicts
0

CVE-2026-57767

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

PUBLISHED
Vendor
CodeCabin.io
Product
WP Google Maps Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-57766

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

PUBLISHED
Vendor
XplodedThemes
Product
WPIDE – File Manager & Code Editor
Provider severity
HIGH
Conflicts
0

CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

PUBLISHED
Vendor
Levelfourdevelopment
Product
WP EasyCart
Provider severity
HIGH
Conflicts
0

CVE-2026-57764

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

PUBLISHED
Vendor
Surbma
Product
Surbma | Yoast SEO Breadcrumb Shortcode
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57763

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

PUBLISHED
Vendor
Gordon Böhme
Product
Structured Content
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57762

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

PUBLISHED
Vendor
Andrew Fiebert
Product
Simple URLs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57761

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

PUBLISHED
Vendor
BlueAstralThemes
Product
SEOWP
Provider severity
HIGH
Conflicts
0

CVE-2026-57760

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

PUBLISHED
Vendor
Sendcloud
Product
Sendcloud Shipping
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5776

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

PUBLISHED
Vendor
Unknown
Product
Email Encoder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57759

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

PUBLISHED
Vendor
Metagauss
Product
ProfileGrid
Provider severity
HIGH
Conflicts
0

CVE-2026-57758

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

PUBLISHED
Vendor
BeRocket
Product
Permalink Manager for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-57757

Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

PUBLISHED
Vendor
ploudapp
Product
pCloud WP Backup
Provider severity
HIGH
Conflicts
0

CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

PUBLISHED
Vendor
友人a丶
Product
nicen-localize-image
Provider severity
HIGH
Conflicts
0

CVE-2026-57755

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

PUBLISHED
Vendor
Misbah WP
Product
Mosaic Gallery &#8211; Advanced Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57754

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

PUBLISHED
Vendor
Livemesh
Product
Livemesh Addons for WPBakery Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57753

Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

PUBLISHED
Vendor
Nathanbarry
Product
Kit (formerly ConvertKit) for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

PUBLISHED
Vendor
iNET
Product
iNET Webkit
Provider severity
HIGH
Conflicts
0

CVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

PUBLISHED
Vendor
Heateor Support
Product
Heateor Social Login
Provider severity
HIGH
Conflicts
0

CVE-2026-57750

Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

PUBLISHED
Vendor
Keksdieb
Product
ez Form Calculator Premium
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57749

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

PUBLISHED
Vendor
ThemeBoy
Product
SportsPress Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-57748

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

PUBLISHED
Vendor
Shopify Help Center
Product
Shopify
Provider severity
HIGH
Conflicts
0

CVE-2026-57747

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

PUBLISHED
Vendor
ThemeREX
Product
Booked
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57746

Subscriber Broken Access Control in Booked <= 3.0.0 versions.

PUBLISHED
Vendor
ThemeREX
Product
Booked
Provider severity
HIGH
Conflicts
0

CVE-2026-57745

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

PUBLISHED
Vendor
stmcan
Product
RT-Theme 18 | Extensions
Provider severity
HIGH
Conflicts
0

CVE-2026-57744

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

PUBLISHED
Vendor
stmcan
Product
RT-Theme 18 | Extensions
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57743

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

PUBLISHED
Vendor
stmcan
Product
RT-Theme 18 | Extensions
Provider severity
HIGH
Conflicts
0

CVE-2026-57741

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

PUBLISHED
Vendor
AcyMailing Newsletter Team
Product
AcyMailing SMTP Newsletter
Provider severity
HIGH
Conflicts
0

CVE-2026-57740

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

PUBLISHED
Vendor
AcyMailing Newsletter Team
Product
AcyMailing SMTP Newsletter
Provider severity
HIGH
Conflicts
0

CVE-2026-5774

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

PUBLISHED
Vendor
Canonical
Product
Juju
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

PUBLISHED
Vendor
AcyMailing Newsletter Team
Product
AcyMailing SMTP Newsletter
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

PUBLISHED
Vendor
axiomthemes
Product
777
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57737

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.

PUBLISHED
Vendor
Averta LTD
Product
Shortcodes and extra features for Phlox theme
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57736

Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.

PUBLISHED
Vendor
HubSpot
Product
HubSpot
Provider severity
HIGH
Conflicts
0

CVE-2026-57735

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

PUBLISHED
Vendor
Soflyy
Product
Breakdance
Provider severity
HIGH
Conflicts
0

CVE-2026-57734

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

PUBLISHED
Vendor
tagDiv
Product
tagDiv Composer
Provider severity
HIGH
Conflicts
0

CVE-2026-57733

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.

PUBLISHED
Vendor
tagDiv
Product
tagDiv Cloud Library
Provider severity
HIGH
Conflicts
0

CVE-2026-57732

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.

PUBLISHED
Vendor
tagDiv
Product
tagDiv Opt-In Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-57731

Contributor Broken Access Control in Flatsome <= 3.20.5 versions.

PUBLISHED
Vendor
UX-themes
Product
Flatsome
Provider severity
MEDIUM
Conflicts
0