Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,432
Critical1,287
High4,421
Medium12,480
Reset
Showing 4101-4120 of 18432 records
Threat Entry Updated 2026-06-17

CVE-2026-22374 - Zio Alberto Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Zio Alberto zioalberto allows PHP Local File Inclusion.This issue affects Zio Alberto: from n/a through

PLUGIN Zio Alberto

CVE-2026-22374

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22373 - Fooddy Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fooddy fooddy allows PHP Local File Inclusion.This issue affects Fooddy: from n/a through

PLUGIN Fooddy

CVE-2026-22373

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22372 - Isida Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Isida isida allows PHP Local File Inclusion.This issue affects Isida: from n/a through

PLUGIN Isida

CVE-2026-22372

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22371 - Gustavo Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gustavo gustavo allows PHP Local File Inclusion.This issue affects Gustavo: from n/a through

PLUGIN Gustavo

CVE-2026-22371

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22370 - Marveland Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Marveland marveland allows PHP Local File Inclusion.This issue affects Marveland: from n/a through

PLUGIN Marveland

CVE-2026-22370

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22369 - Ironfit Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ironfit ironfit allows PHP Local File Inclusion.This issue affects Ironfit: from n/a through

PLUGIN Ironfit

CVE-2026-22369

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22365 - Soleng Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Soleng soleng allows PHP Local File Inclusion.This issue affects Soleng: from n/a through

PLUGIN Soleng

CVE-2026-22365

CRITICAL CVSS 9.8 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22368 - Redy Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Redy redy allows PHP Local File Inclusion.This issue affects Redy: from n/a through

PLUGIN Redy

CVE-2026-22368

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22367 - Coworking Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Coworking coworking allows PHP Local File Inclusion.This issue affects Coworking: from n/a through

PLUGIN Coworking

CVE-2026-22367

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22366 - Jude Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Jude jude allows PHP Local File Inclusion.This issue affects Jude: from n/a through

PLUGIN Jude

CVE-2026-22366

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22364 - SevenTrees Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes SevenTrees seventrees allows PHP Local File Inclusion.This issue affects SevenTrees: from n/a through

PLUGIN SevenTrees

CVE-2026-22364

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22363 - Rhodos Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rhodos rhodos allows PHP Local File Inclusion.This issue affects Rhodos: from n/a through

PLUGIN Rhodos

CVE-2026-22363

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22362 - Photolia Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Photolia photolia allows PHP Local File Inclusion.This issue affects Photolia: from n/a through

PLUGIN Photolia

CVE-2026-22362

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22354 - Woocommerce Category Banner Management Plugin

Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object Injection.This issue affects Woocommerce Category Banner Management: from n/a through

PLUGIN Woocommerce Category Banner Management

CVE-2026-22354

HIGH CVSS 8.8 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22361 - A-Mart Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes A-Mart a-mart allows PHP Local File Inclusion.This issue affects A-Mart: from n/a through

PLUGIN A-Mart

CVE-2026-22361

HIGH CVSS 8.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22356 - Jetpack CRM Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through

PLUGIN Jetpack CRM

CVE-2026-22356

HIGH CVSS 7.5 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22351 - WP FullCalendar Plugin

Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through

PLUGIN WP FullCalendar

CVE-2026-22351

HIGH CVSS 7.5 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22357 - Link Whisper Free Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through

PLUGIN Link Whisper Free

CVE-2026-22357

HIGH CVSS 7.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22352 - Persian Woocommerce SMS Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PersianScript Persian Woocommerce SMS persian-woocommerce-sms allows Reflected XSS.This issue affects Persian Woocommerce SMS: from n/a through

PLUGIN Persian Woocommerce SMS

CVE-2026-22352

HIGH CVSS 7.1 2026-02-20
Threat Entry Updated 2026-06-17

CVE-2026-22346 - Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin

Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow slider-responsive-slideshow allows Object Injection.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through

PLUGIN Slider Responsive Slideshow – Image slider, Gallery slideshow

CVE-2026-22346

HIGH CVSS 8.8 2026-02-20
Scroll to top