Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3001-3020 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-25400 - Apicona Plugin

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through

PLUGIN Apicona

CVE-2026-25400

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25406 - Tutor LMS Pro Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through

PLUGIN Tutor LMS Pro

CVE-2026-25406

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25401 - WPCargo Track & Trace Plugin

Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through

PLUGIN WPCargo Track & Trace

CVE-2026-25401

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25397 - File Uploader for WooCommerce Plugin

Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through

PLUGIN File Uploader for WooCommerce

CVE-2026-25397

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25396 - Commerce Coinbase For WooCommerce Plugin

Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooCommerce: from n/a through

PLUGIN Commerce Coinbase For WooCommerce

CVE-2026-25396

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25398 - Elementor Plugin

Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vertex Addons for Elementor: from n/a through

PLUGIN Elementor

CVE-2026-25398

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25377 - Addon Jobsearch Chat Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through

PLUGIN Addon Jobsearch Chat

CVE-2026-25377

CRITICAL CVSS 9.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25382 - IdealAuto Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes IdealAuto idealauto allows PHP Local File Inclusion.This issue affects IdealAuto: from n/a through < 3.8.6.

PLUGIN IdealAuto

CVE-2026-25382

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25381 - LoveDate Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects LoveDate: from n/a through < 3.8.6.

PLUGIN LoveDate

CVE-2026-25381

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25380 - Feedy Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Feedy feedy allows PHP Local File Inclusion.This issue affects Feedy: from n/a through < 2.1.5.

PLUGIN Feedy

CVE-2026-25380

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25379 - StreamVid Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes StreamVid streamvid allows PHP Local File Inclusion.This issue affects StreamVid: from n/a through < 6.8.6.

PLUGIN StreamVid

CVE-2026-25379

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25383 - KiviCare Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through

PLUGIN KiviCare

CVE-2026-25383

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25390 - New User Approve Plugin

Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through

PLUGIN New User Approve

CVE-2026-25390

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25366 - Woody ad snippets Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through

PLUGIN Woody ad snippets

CVE-2026-25366

CRITICAL CVSS 9.9 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25371 - Lumise Product Designer Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9.

PLUGIN Lumise Product Designer

CVE-2026-25371

CRITICAL CVSS 9.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25360 - Vex Plugin

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

PLUGIN Vex

CVE-2026-25360

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25359 - Pendulum Plugin

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.

PLUGIN Pendulum

CVE-2026-25359

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25376 - Addon Jobsearch Chat Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows Reflected XSS.This issue affects Addon Jobsearch Chat: from n/a through

PLUGIN Addon Jobsearch Chat

CVE-2026-25376

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25373 - Vayvo Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/a through < 6.8.

PLUGIN Vayvo

CVE-2026-25373

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25361 - WpEvently Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through

PLUGIN WpEvently

CVE-2026-25361

HIGH CVSS 7.1 2026-03-25
Scroll to top