Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-28106

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a before 5.4.20.

PUBLISHED
Vendor
Kings Plugins
Product
B2BKing Premium
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28105

Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7.

PUBLISHED
Vendor
ThemeREX
Product
Good Energy
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28104

Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Site Suggest: from n/a through <= 1.3.9.

PUBLISHED
Vendor
Aryan Shirani Bid Abadi
Product
Site Suggest
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28103

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows Reflected XSS.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.5.

PUBLISHED
Vendor
LambertGroup
Product
LBG Zoominoutslider
Provider severity
HIGH
Conflicts
0

CVE-2026-28102

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Classic uberSlider_classic allows Reflected XSS.This issue affects UberSlider Classic: from n/a through <= 2.5.

PUBLISHED
Vendor
LambertGroup
Product
UberSlider Classic
Provider severity
HIGH
Conflicts
0

CVE-2026-28101

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider MouseInteraction uberSlider_mouseinteraction allows Reflected XSS.This issue affects UberSlider MouseInteraction: from n/a through <= 2.3.

PUBLISHED
Vendor
LambertGroup
Product
UberSlider MouseInteraction
Provider severity
HIGH
Conflicts
0

CVE-2026-28100

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider PerpetuumMobile uberSlider_perpetuummobile allows Reflected XSS.This issue affects UberSlider PerpetuumMobile: from n/a through <= 2.3.

PUBLISHED
Vendor
LambertGroup
Product
UberSlider PerpetuumMobile
Provider severity
HIGH
Conflicts
0

CVE-2026-2810

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

PUBLISHED
Vendor
Netskope
Product
Client
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28099

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Ultra uberSlider_ultra allows Reflected XSS.This issue affects UberSlider Ultra: from n/a through <= 2.3.

PUBLISHED
Vendor
LambertGroup
Product
UberSlider Ultra
Provider severity
HIGH
Conflicts
0

CVE-2026-28098

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Save Life save-life allows PHP Local File Inclusion.This issue affects Save Life: from n/a through <= 1.2.13.

PUBLISHED
Vendor
ThemeREX
Product
Save Life
Provider severity
HIGH
Conflicts
0

CVE-2026-28097

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Artrium artrium allows PHP Local File Inclusion.This issue affects Artrium: from n/a through <= 1.0.14.

PUBLISHED
Vendor
ThemeREX
Product
Artrium
Provider severity
HIGH
Conflicts
0

CVE-2026-28096

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX WealthCo wealthco allows PHP Local File Inclusion.This issue affects WealthCo: from n/a through <= 2.18.

PUBLISHED
Vendor
ThemeREX
Product
WealthCo
Provider severity
HIGH
Conflicts
0

CVE-2026-28095

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Marcell marcell allows PHP Local File Inclusion.This issue affects Marcell: from n/a through <= 1.2.14.

PUBLISHED
Vendor
ThemeREX
Product
Marcell
Provider severity
HIGH
Conflicts
0

CVE-2026-28094

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX RexCoin rexcoin allows PHP Local File Inclusion.This issue affects RexCoin: from n/a through <= 1.2.6.

PUBLISHED
Vendor
ThemeREX
Product
RexCoin
Provider severity
HIGH
Conflicts
0

CVE-2026-28093

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Ozisti ozisti allows PHP Local File Inclusion.This issue affects Ozisti: from n/a through <= 1.1.10.

PUBLISHED
Vendor
ThemeREX
Product
Ozisti
Provider severity
HIGH
Conflicts
0

CVE-2026-28092

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Sounder sounder allows PHP Local File Inclusion.This issue affects Sounder: from n/a through <= 1.3.11.

PUBLISHED
Vendor
ThemeREX
Product
Sounder
Provider severity
HIGH
Conflicts
0

CVE-2026-28091

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coleo coleo allows PHP Local File Inclusion.This issue affects Coleo: from n/a through <= 1.1.7.

PUBLISHED
Vendor
ThemeREX
Product
Coleo
Provider severity
HIGH
Conflicts
0

CVE-2026-28090

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gamezone gamezone allows PHP Local File Inclusion.This issue affects Gamezone: from n/a through <= 1.1.11.

PUBLISHED
Vendor
ThemeREX
Product
Gamezone
Provider severity
HIGH
Conflicts
0

CVE-2026-2809

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

PUBLISHED
Vendor
Netskope
Product
Endpoint DLP Module for Netskope Client
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28089

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Daiquiri daiquiri allows PHP Local File Inclusion.This issue affects Daiquiri: from n/a through <= 1.2.4.

PUBLISHED
Vendor
ThemeREX
Product
Daiquiri
Provider severity
HIGH
Conflicts
0

CVE-2026-28088

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aqualots aqualots allows PHP Local File Inclusion.This issue affects Aqualots: from n/a through <= 1.1.6.

PUBLISHED
Vendor
ThemeREX
Product
Aqualots
Provider severity
HIGH
Conflicts
0

CVE-2026-28087

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Filmax filmax allows PHP Local File Inclusion.This issue affects Filmax: from n/a through <= 1.1.11.

PUBLISHED
Vendor
ThemeREX
Product
Filmax
Provider severity
HIGH
Conflicts
0

CVE-2026-28086

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Run Gran run-gran allows PHP Local File Inclusion.This issue affects Run Gran: from n/a through <= 2.0.

PUBLISHED
Vendor
ThemeREX
Product
Run Gran
Provider severity
HIGH
Conflicts
0

CVE-2026-28085

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Mahogany mahogany allows PHP Local File Inclusion.This issue affects Mahogany: from n/a through <= 2.9.

PUBLISHED
Vendor
ThemeREX
Product
Mahogany
Provider severity
HIGH
Conflicts
0

CVE-2026-28084

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Bazinga bazinga allows PHP Local File Inclusion.This issue affects Bazinga: from n/a through <= 1.1.9.

PUBLISHED
Vendor
ThemeREX
Product
Bazinga
Provider severity
HIGH
Conflicts
0

CVE-2026-28083

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: from n/a through <= 3.20.5.

PUBLISHED
Vendor
UX-themes
Product
Flatsome
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28081

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Windsor windsor allows PHP Local File Inclusion.This issue affects Windsor: from n/a through <= 2.5.0.

PUBLISHED
Vendor
ThemeREX
Product
Windsor
Provider severity
HIGH
Conflicts
0

CVE-2026-28080

Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.

PUBLISHED
Vendor
Rank Math
Product
Rank Math SEO PRO
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2808

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

PUBLISHED
Vendor
HashiCorp, HashiCorp
Product
Consul Enterprise, Consul
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28079

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Conquerors conquerors allows PHP Local File Inclusion.This issue affects Conquerors: from n/a through <= 1.2.13.

PUBLISHED
Vendor
axiomthemes
Product
Conquerors
Provider severity
HIGH
Conflicts
0

CVE-2026-28078

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisting allows Path Traversal.This issue affects uListing: from n/a through <= 2.2.0.

PUBLISHED
Vendor
Stylemix
Product
uListing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28077

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Vapester vapester allows PHP Local File Inclusion.This issue affects Vapester: from n/a through <= 1.1.10.

PUBLISHED
Vendor
ThemeREX
Product
Vapester
Provider severity
HIGH
Conflicts
0

CVE-2026-28076

Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.

PUBLISHED
Vendor
Frenify
Product
Guff
Provider severity
HIGH
Conflicts
0

CVE-2026-28075

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in p-themes Porto porto allows Reflected XSS.This issue affects Porto: from n/a through <= 7.6.2.

PUBLISHED
Vendor
p-themes
Product
Porto
Provider severity
HIGH
Conflicts
0

CVE-2026-28074

Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0.

PUBLISHED
Vendor
ThemeREX
Product
Pizza House
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28073

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected XSS.This issue affects WP eMember: from n/a through v10.2.2.

PUBLISHED
Vendor
Tips and Tricks HQ
Product
WP eMember
Provider severity
HIGH
Conflicts
0

CVE-2026-28072

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixFort pixfort Core pixfort-core allows Reflected XSS.This issue affects pixfort Core: from n/a through <= 3.2.22.

PUBLISHED
Vendor
PixFort
Product
pixfort Core
Provider severity
HIGH
Conflicts
0

CVE-2026-28071

Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pixfort Core: from n/a through <= 3.2.22.

PUBLISHED
Vendor
PixFort
Product
pixfort Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28070

Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2.

PUBLISHED
Vendor
Tips and Tricks HQ
Product
WP eMember
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2807

A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Firefox, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Thunderbird, Red Hat Enterprise Linux 10
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-28069

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Le Truffe letruffe allows PHP Local File Inclusion.This issue affects Le Truffe: from n/a through <= 1.1.7.

PUBLISHED
Vendor
ThemeREX
Product
Le Truffe
Provider severity
HIGH
Conflicts
0

CVE-2026-28068

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Rhythmo rhythmo allows PHP Local File Inclusion.This issue affects Rhythmo: from n/a through <= 1.3.4.

PUBLISHED
Vendor
ThemeREX
Product
Rhythmo
Provider severity
HIGH
Conflicts
0

CVE-2026-28067

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Bassein bassein allows PHP Local File Inclusion.This issue affects Bassein: from n/a through <= 1.0.15.

PUBLISHED
Vendor
ThemeREX
Product
Bassein
Provider severity
HIGH
Conflicts
0

CVE-2026-28066

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Legrand legrand allows PHP Local File Inclusion.This issue affects Legrand: from n/a through <= 2.17.

PUBLISHED
Vendor
ThemeREX
Product
Legrand
Provider severity
HIGH
Conflicts
0

CVE-2026-28065

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Eject eject allows PHP Local File Inclusion.This issue affects Eject: from n/a through <= 2.17.

PUBLISHED
Vendor
ThemeREX
Product
Eject
Provider severity
HIGH
Conflicts
0

CVE-2026-28064

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Edge Decor edge-decor allows PHP Local File Inclusion.This issue affects Edge Decor: from n/a through <= 2.2.

PUBLISHED
Vendor
ThemeREX
Product
Edge Decor
Provider severity
HIGH
Conflicts
0

CVE-2026-28063

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1.

PUBLISHED
Vendor
ThemeREX
Product
Asia Garden
Provider severity
HIGH
Conflicts
0

CVE-2026-28062

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Happy Baby happy-baby allows PHP Local File Inclusion.This issue affects Happy Baby: from n/a through <= 1.2.12.

PUBLISHED
Vendor
ThemeREX
Product
Happy Baby
Provider severity
HIGH
Conflicts
0

CVE-2026-28061

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tiger Claw tiger-claw allows PHP Local File Inclusion.This issue affects Tiger Claw: from n/a through <= 1.1.14.

PUBLISHED
Vendor
ThemeREX
Product
Tiger Claw
Provider severity
HIGH
Conflicts
0

CVE-2026-28060

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX S.King stephanie-king allows PHP Local File Inclusion.This issue affects S.King: from n/a through <= 1.5.3.

PUBLISHED
Vendor
ThemeREX
Product
S.King
Provider severity
HIGH
Conflicts
0