Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39681

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows PHP Local File Inclusion.This issue affects Homeo: from n/a through <= 1.2.59.

PUBLISHED
Vendor
ApusTheme
Product
Homeo
Provider severity
HIGH
Conflicts
0

CVE-2026-39680

Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through <= 1.1.1.

PUBLISHED
Vendor
MWP Development
Product
Diet Calorie Calculator
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3968

A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
AutohomeCorp
Product
frostmourne
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39679

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allows PHP Local File Inclusion.This issue affects Freeio: from n/a through <= 1.3.21.

PUBLISHED
Vendor
ApusTheme
Product
Freeio
Provider severity
HIGH
Conflicts
0

CVE-2026-39678

Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5.

PUBLISHED
Vendor
DOTonPAPER
Product
Pinpoint Booking System
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39677

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through <= 3.9.

PUBLISHED
Vendor
Creatives_Planet
Product
Emphires
Provider severity
HIGH
Conflicts
0

CVE-2026-39676

Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.

PUBLISHED
Vendor
Shahjada
Product
Download Manager
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39675

Missing Authorization vulnerability in webmuehle Court Reservation court-reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Court Reservation: from n/a through <= 1.10.11.

PUBLISHED
Vendor
webmuehle
Product
Court Reservation
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39674

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1.

PUBLISHED
Vendor
Manoj Kumar
Product
MK Google Directions
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39673

Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iZooto: from n/a through <= 3.7.20.

PUBLISHED
Vendor
shrikantkale
Product
iZooto
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39672

Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1.

PUBLISHED
Vendor
shiptime
Product
ShipTime: Discounted Shipping Rates
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39671

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross Site Request Forgery.This issue affects Extra Fees Plugin for WooCommerce: from n/a through <= 4.3.3.

PUBLISHED
Vendor
Dotstore
Product
Extra Fees Plugin for WooCommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-39670

Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0.

PUBLISHED
Vendor
Brecht
Product
Visual Link Preview
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3967

A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. This manipulation causes deserialization. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but di

PUBLISHED
Vendor
Alfresco
Product
Activiti
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39669

Missing Authorization vulnerability in NitroPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NitroPack: from n/a through 1.19.3.

PUBLISHED
Vendor
NitroPack
Product
NitroPack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39668

Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through <= 1.0.6.

PUBLISHED
Vendor
g5theme
Product
Book Previewer for Woocommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39667

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through <= 1.7.0.

PUBLISHED
Vendor
Jongmyoung Kim
Product
Korea SNS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39666

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allows DOM-Based XSS.This issue affects Hello Bar Popup Builder: from n/a through <= 1.5.1.

PUBLISHED
Vendor
telepathy
Product
Hello Bar Popup Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39665

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image allows DOM-Based XSS.This issue affects SEO Friendly Images: from n/a through <= 3.0.5.

PUBLISHED
Vendor
Vladimir Prelovac
Product
SEO Friendly Images
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39664

Missing Authorization vulnerability in leadrebel Leadrebel leadrebel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadrebel: from n/a through <= 1.0.2.

PUBLISHED
Vendor
leadrebel
Product
Leadrebel
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39663

Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5.

PUBLISHED
Vendor
themetechmount
Product
TrueBooker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39662

Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through <= 2.5.6.

PUBLISHED
Vendor
ProWCPlugins
Product
Product Price by Formula for WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39661

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.

PUBLISHED
Vendor
Magentech
Product
SW Core
Provider severity
HIGH
Conflicts
0

CVE-2026-3966

A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. The manipulation of the argument MediaServer.streamIp results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure

PUBLISHED
Vendor
648540858
Product
wvp-GB28181-pro
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39658

Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through <= 1.5.12.

PUBLISHED
Vendor
Coding Panda
Product
Panda Pods Repeater Field
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39657

Missing Authorization vulnerability in leadlovers leadlovers forms leadlovers-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects leadlovers forms: from n/a through <= 1.0.2.

PUBLISHED
Vendor
leadlovers
Product
leadlovers forms
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39656

Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommerce: from n/a through <= 4.8.2.

PUBLISHED
Vendor
Razorpay
Product
Razorpay for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39655

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

PUBLISHED
Vendor
TeconceTheme
Product
Mayosis Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39654

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap wp-simple-html-sitemap allows DOM-Based XSS.This issue affects WP Simple HTML Sitemap: from n/a through <= 3.8.

PUBLISHED
Vendor
Ashish Ajani
Product
WP Simple HTML Sitemap
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39653

Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Conferencing with Zoom: from n/a through <= 4.6.6.

PUBLISHED
Vendor
Deepen Bajracharya
Product
Video Conferencing with Zoom
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39652

Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: from n/a through <= 1.3.

PUBLISHED
Vendor
igms
Product
iGMS Direct Booking
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39651

Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through <= 4.12.0.

PUBLISHED
Vendor
TotalSuite
Product
Total Poll Lite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39650

Missing Authorization vulnerability in Unitech Web UnitechPay unitechpay-paiements-mobile-money allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnitechPay: from n/a through <= 1.0.2.

PUBLISHED
Vendor
Unitech Web
Product
UnitechPay
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3965

A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.20.2 is able to address this issue. The identifier of the patch is 6bec52dca158481258315ba0fc2f11206df7b719. It is advisable t

PUBLISHED
Vendor
whyour
Product
qinglong
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39649

Missing Authorization vulnerability in themebeez Royale News royale-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royale News: from n/a through <= 2.2.4.

PUBLISHED
Vendor
themebeez
Product
Royale News
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39648

Missing Authorization vulnerability in themebeez Cream Blog cream-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cream Blog: from n/a through <= 2.1.7.

PUBLISHED
Vendor
themebeez
Product
Cream Blog
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39647

Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11.

PUBLISHED
Vendor
sonaar
Product
MP3 Audio Player for Music, Radio & Podcast by Sonaar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39646

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map leaflet-map allows Stored XSS.This issue affects Leaflet Map: from n/a through <= 3.4.4.

PUBLISHED
Vendor
bozdoz
Product
Leaflet Map
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39645

Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Server Side Request Forgery.This issue affects GlobalPayments WooCommerce: from n/a through <= 1.18.0.

PUBLISHED
Vendor
Global Payments
Product
GlobalPayments WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39644

Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wp Ultimate Review: from n/a through <= 2.3.8.

PUBLISHED
Vendor
Roxnor
Product
Wp Ultimate Review
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39643

Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13.

PUBLISHED
Vendor
Payment Plugins
Product
Payment Plugins for PayPal WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39642

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.

PUBLISHED
Vendor
SpabRice
Product
Nyla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39641

Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This issue affects Blackfyre: from n/a through <= 2.5.4.

PUBLISHED
Vendor
Skywarrior
Product
Blackfyre
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39640

Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.

PUBLISHED
Vendor
mndpsingh287
Product
Theme Editor
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3964

A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Chat API Endpoint. Executing a manipulation of the argument Message can lead to os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
OpenAkita
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39639

Missing Authorization vulnerability in redpixelstudios RPS Include Content rps-include-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RPS Include Content: from n/a through <= 1.2.2.

PUBLISHED
Vendor
redpixelstudios
Product
RPS Include Content
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39638

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.14.

PUBLISHED
Vendor
Themeum
Product
Qubely
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39637

Missing Authorization vulnerability in SpabRice Mogi mogi allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mogi: from n/a through <= 1.2.3.

PUBLISHED
Vendor
SpabRice
Product
Mogi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39636

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through <= 9.0.

PUBLISHED
Vendor
livemesh
Product
Livemesh Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39635

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <= 3.5.5.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Magazine
Provider severity
MEDIUM
Conflicts
1