Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-22453

Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3.

PUBLISHED
Vendor
ThemeREX
Product
Pets Club
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22452

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hoverex hoverex allows PHP Local File Inclusion.This issue affects Hoverex: from n/a through <= 1.5.10.

PUBLISHED
Vendor
ThemeREX
Product
Hoverex
Provider severity
HIGH
Conflicts
0

CVE-2026-22451

Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through <= 1.4.7.

PUBLISHED
Vendor
AncoraThemes
Product
Handyman
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22450

Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.

PUBLISHED
Vendor
Select-Themes
Product
Don Peppe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2245

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The name of the patch is fd7271bae238ccb3ae8a71304ea64f0886324925. It is best practice to apply a patch to resolve this issue.

PUBLISHED
Vendor
n/a
Product
CCExtractor
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-22449

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through <= 1.3.

PUBLISHED
Vendor
Select-Themes
Product
Don Peppe
Provider severity
HIGH
Conflicts
0

CVE-2026-22448

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal.This issue affects PitchPrint: from n/a through <= 11.1.2.

PUBLISHED
Vendor
flexcubed
Product
PitchPrint
Provider severity
HIGH
Conflicts
0

CVE-2026-22447

Missing Authorization vulnerability in Select-Themes Prowess prowess allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Prowess: from n/a through <= 1.8.1.

PUBLISHED
Vendor
Select-Themes
Product
Prowess
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22446

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowess allows PHP Local File Inclusion.This issue affects Prowess: from n/a through <= 1.8.1.

PUBLISHED
Vendor
Select-Themes
Product
Prowess
Provider severity
HIGH
Conflicts
0

CVE-2026-22445

Missing Authorization vulnerability in Proptech Plugin Apimo Connector apimo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apimo Connector: from n/a through <= 2.6.5.2.

PUBLISHED
Vendor
Proptech Plugin
Product
Apimo Connector
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22444

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security setting https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xml.html#the-solr-element .  These read-only accesses can allow users to create cores using unexpected configsets if any are accessible via the fil

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Solr
Provider severity
HIGH
Conflicts
0

CVE-2026-22443

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Alliance alliance allows PHP Local File Inclusion.This issue affects Alliance: from n/a through <= 3.1.1.

PUBLISHED
Vendor
ThemeREX
Product
Alliance
Provider severity
HIGH
Conflicts
0

CVE-2026-22442

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LaunchandSell Tribe tribe allows PHP Local File Inclusion.This issue affects Tribe: from n/a through <= 1.7.3.

PUBLISHED
Vendor
LaunchandSell
Product
Tribe
Provider severity
HIGH
Conflicts
0

CVE-2026-22441

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Zentrum zentrum allows PHP Local File Inclusion.This issue affects Zentrum: from n/a through <= 1.0.

PUBLISHED
Vendor
Elated-Themes
Product
Zentrum
Provider severity
HIGH
Conflicts
0

CVE-2026-22440

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thecs thecs allows Reflected XSS.This issue affects Thecs: from n/a through <= 1.4.7.

PUBLISHED
Vendor
foreverpinetree
Product
Thecs
Provider severity
HIGH
Conflicts
0

CVE-2026-2244

A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this.

PUBLISHED
Vendor
Google Cloud
Product
Vertex AI Workbench
Provider severity
HIGH
Conflicts
0

CVE-2026-22439

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Green Planet green-planet allows PHP Local File Inclusion.This issue affects Green Planet: from n/a through <= 1.1.14.

PUBLISHED
Vendor
AncoraThemes
Product
Green Planet
Provider severity
HIGH
Conflicts
0

CVE-2026-22438

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affects TheBi: from n/a through <= 1.0.5.

PUBLISHED
Vendor
foreverpinetree
Product
TheBi
Provider severity
HIGH
Conflicts
0

CVE-2026-22437

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Playa playa allows PHP Local File Inclusion.This issue affects Playa: from n/a through <= 1.3.9.

PUBLISHED
Vendor
AncoraThemes
Product
Playa
Provider severity
HIGH
Conflicts
0

CVE-2026-22436

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Helvig helvig allows PHP Local File Inclusion.This issue affects Helvig: from n/a through <= 1.0.

PUBLISHED
Vendor
Elated-Themes
Product
Helvig
Provider severity
HIGH
Conflicts
0

CVE-2026-22435

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ElectroServ electroserv allows PHP Local File Inclusion.This issue affects ElectroServ: from n/a through <= 1.3.2.

PUBLISHED
Vendor
AncoraThemes
Product
ElectroServ
Provider severity
HIGH
Conflicts
0

CVE-2026-22434

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.

PUBLISHED
Vendor
AncoraThemes
Product
Crown Art
Provider severity
HIGH
Conflicts
0

CVE-2026-22433

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CloudMe cloudme allows PHP Local File Inclusion.This issue affects CloudMe: from n/a through <= 1.2.2.

PUBLISHED
Vendor
AncoraThemes
Product
CloudMe
Provider severity
HIGH
Conflicts
0

CVE-2026-22432

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Woopy woopy allows PHP Local File Inclusion.This issue affects Woopy: from n/a through <= 1.2.

PUBLISHED
Vendor
AncoraThemes
Product
Woopy
Provider severity
HIGH
Conflicts
0

CVE-2026-22431

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wabi-Sabi wabi-sabi allows PHP Local File Inclusion.This issue affects Wabi-Sabi: from n/a through <= 1.2.

PUBLISHED
Vendor
AncoraThemes
Product
Wabi-Sabi
Provider severity
HIGH
Conflicts
0

CVE-2026-22430

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Verdure verdure allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Verdure: from n/a through <= 1.6.

PUBLISHED
Vendor
Mikado-Themes
Product
Verdure
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2243

A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22429

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Verdure verdure allows PHP Local File Inclusion.This issue affects Verdure: from n/a through <= 1.6.

PUBLISHED
Vendor
Mikado-Themes
Product
Verdure
Provider severity
HIGH
Conflicts
0

CVE-2026-22428

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Tooth Fairy tooth-fairy allows PHP Local File Inclusion.This issue affects Tooth Fairy: from n/a through <= 1.16.

PUBLISHED
Vendor
AncoraThemes
Product
Tooth Fairy
Provider severity
HIGH
Conflicts
0

CVE-2026-22427

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes GoTravel gotravel allows PHP Local File Inclusion.This issue affects GoTravel: from n/a through <= 2.1.

PUBLISHED
Vendor
Mikado-Themes
Product
GoTravel
Provider severity
HIGH
Conflicts
0

CVE-2026-22426

Authorization Bypass Through User-Controlled Key vulnerability in Elated-Themes Sweet Jane sweetjane allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sweet Jane: from n/a through <= 1.2.

PUBLISHED
Vendor
Elated-Themes
Product
Sweet Jane
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22425

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Sweet Jane sweetjane allows PHP Local File Inclusion.This issue affects Sweet Jane: from n/a through <= 1.2.

PUBLISHED
Vendor
Elated-Themes
Product
Sweet Jane
Provider severity
HIGH
Conflicts
0

CVE-2026-22424

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Shaha shaha allows PHP Local File Inclusion.This issue affects Shaha: from n/a through <= 1.1.2.

PUBLISHED
Vendor
AncoraThemes
Product
Shaha
Provider severity
HIGH
Conflicts
0

CVE-2026-22423

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 1.8.

PUBLISHED
Vendor
Select-Themes
Product
SetSail
Provider severity
HIGH
Conflicts
0

CVE-2026-22422

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a through <= 3.4.1.

PUBLISHED
Vendor
wpeverest
Product
Everest Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22421

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Quantum quantum allows PHP Local File Inclusion.This issue affects Quantum: from n/a through <= 1.0.

PUBLISHED
Vendor
AncoraThemes
Product
Quantum
Provider severity
HIGH
Conflicts
0

CVE-2026-22420

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Horizon horizon allows PHP Local File Inclusion.This issue affects Horizon: from n/a through <= 1.1.

PUBLISHED
Vendor
AncoraThemes
Product
Horizon
Provider severity
HIGH
Conflicts
0

CVE-2026-2242

A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/core/specials.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called c43e06672cd9dacf2122c99f362120a17c34b391. It is advisable to implement a patch to correct this issue.

PUBLISHED
Vendor
janet-lang
Product
janet
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-22419

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Honor honor allows PHP Local File Inclusion.This issue affects Honor: from n/a through <= 2.3.

PUBLISHED
Vendor
AncoraThemes
Product
Honor
Provider severity
HIGH
Conflicts
0

CVE-2026-22418

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Great Lotus great-lotus allows PHP Local File Inclusion.This issue affects Great Lotus: from n/a through <= 1.3.1.

PUBLISHED
Vendor
AncoraThemes
Product
Great Lotus
Provider severity
HIGH
Conflicts
0

CVE-2026-22417

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through < 3.1.11.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Wedding
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22416

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes FixTeam fixteam allows PHP Local File Inclusion.This issue affects FixTeam: from n/a through <= 1.5.0.

PUBLISHED
Vendor
AncoraThemes
Product
FixTeam
Provider severity
HIGH
Conflicts
0

CVE-2026-22415

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes The Mounty the-mounty allows PHP Local File Inclusion.This issue affects The Mounty: from n/a through <= 1.1.

PUBLISHED
Vendor
AncoraThemes
Product
The Mounty
Provider severity
HIGH
Conflicts
0

CVE-2026-22414

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Marra marra allows PHP Local File Inclusion.This issue affects Marra: from n/a through <= 1.2.

PUBLISHED
Vendor
Mikado-Themes
Product
Marra
Provider severity
HIGH
Conflicts
0

CVE-2026-22413

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Malgré malgre allows PHP Local File Inclusion.This issue affects Malgré: from n/a through <= 1.0.3.

PUBLISHED
Vendor
Mikado-Themes
Product
Malgré
Provider severity
HIGH
Conflicts
0

CVE-2026-22412

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Eona eona allows PHP Local File Inclusion.This issue affects Eona: from n/a through <= 1.3.

PUBLISHED
Vendor
Mikado-Themes
Product
Eona
Provider severity
HIGH
Conflicts
0

CVE-2026-22411

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dolcino: from n/a through <= 1.6.

PUBLISHED
Vendor
Mikado-Themes
Product
Dolcino
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22410

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dolcino dolcino allows PHP Local File Inclusion.This issue affects Dolcino: from n/a through <= 1.6.

PUBLISHED
Vendor
Mikado-Themes
Product
Dolcino
Provider severity
HIGH
Conflicts
0

CVE-2026-2241

A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is named 0f285855f0e34f9183956be5f16e045f54626bff. To fix this issue, it is recommended to deploy a patch.

PUBLISHED
Vendor
janet-lang
Product
janet
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-22409

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Justicia: from n/a through <= 1.2.

PUBLISHED
Vendor
Mikado-Themes
Product
Justicia
Provider severity
MEDIUM
Conflicts
0