Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3721-3740 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-27340 - Apollo | Night Club, DJ Event WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Apollo | Night Club, DJ Event WordPress Theme apollo allows PHP Local File Inclusion.This issue affects Apollo | Night Club, DJ Event WordPress Theme: from n/a through

THEME Apollo | Night Club, DJ Event WordPress Theme

CVE-2026-27340

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27339 - Buzz Stone | Magazine & Viral Blog WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Buzz Stone | Magazine & Viral Blog WordPress Theme buzzstone allows PHP Local File Inclusion.This issue affects Buzz Stone | Magazine & Viral Blog WordPress Theme: from n/a through

THEME Buzz Stone | Magazine & Viral Blog WordPress Theme

CVE-2026-27339

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27337 - Chronicle - Lifestyle Magazine & Blog WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chronicle - Lifestyle Magazine & Blog WordPress Theme chronicle allows PHP Local File Inclusion.This issue affects Chronicle - Lifestyle Magazine & Blog WordPress Theme: from n/a through

THEME Chronicle - Lifestyle Magazine & Blog WordPress Theme

CVE-2026-27337

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27336 - Consultor | Consulting, Accounting & Legal Counsel WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme consultor allows PHP Local File Inclusion.This issue affects Consultor | Consulting, Accounting & Legal Counsel WordPress Theme: from n/a through

THEME Consultor | Consulting, Accounting & Legal Counsel WordPress Theme

CVE-2026-27336

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-24960 - Charety Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.

PLUGIN Charety

CVE-2026-24960

CRITICAL CVSS 9.9 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27335 - Ekoterra - NonProfit, Green Energy & Ecology Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra allows PHP Local File Inclusion.This issue affects Ekoterra - NonProfit, Green Energy & Ecology Theme: from n/a through

THEME Ekoterra - NonProfit, Green Energy & Ecology Theme

CVE-2026-27335

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27334 - Alchemists Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dan_fisher Alchemists alchemists allows PHP Local File Inclusion.This issue affects Alchemists: from n/a through

PLUGIN Alchemists

CVE-2026-27334

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27326 - AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme: from n/a through

THEME AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme

CVE-2026-27326

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27098 - Au Pair Agency - Babysitting & Nanny Theme

Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through

THEME Au Pair Agency - Babysitting & Nanny Theme

CVE-2026-27098

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27097 - CasaMia | Property Rental Real Estate WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental Real Estate WordPress Theme casamia allows PHP Local File Inclusion.This issue affects CasaMia | Property Rental Real Estate WordPress Theme: from n/a through

THEME CasaMia | Property Rental Real Estate WordPress Theme

CVE-2026-27097

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-24963 - Amelia Plugin

Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through

PLUGIN Amelia

CVE-2026-24963

HIGH CVSS 7.2 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27332 - Agrofood Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Agrofood agrofood allows Reflected XSS.This issue affects Agrofood: from n/a through < 1.4.0.

PLUGIN Agrofood

CVE-2026-27332

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-23802 - AI Engine Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through

PLUGIN AI Engine

CVE-2026-23802

CRITICAL CVSS 9.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-23801 - The Issue Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes The Issue theissue allows PHP Local File Inclusion.This issue affects The Issue: from n/a through

PLUGIN The Issue

CVE-2026-23801

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-24385 - Podlove Web Player Plugin

Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through

PLUGIN Podlove Web Player

CVE-2026-24385

HIGH CVSS 7.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-23799 - Tutor LMS Plugin

Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through

PLUGIN Tutor LMS

CVE-2026-23799

MEDIUM CVSS 6.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-23546 - Classified Listing Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing allows Retrieve Embedded Sensitive Data.This issue affects Classified Listing: from n/a through

PLUGIN Classified Listing

CVE-2026-23546

MEDIUM CVSS 6.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22501 - Mounthood Plugin

Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through

PLUGIN Mounthood

CVE-2026-22501

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22497 - Jardi Plugin

Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through

PLUGIN Jardi

CVE-2026-22497

CRITICAL CVSS 9.8 2026-03-05
Scroll to top