Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-40753 - WordPress component
Unauthenticated PHP Object Injection in EasyMeals
CVE-2026-40753
CVE-2026-40751 - WordPress component
Unauthenticated PHP Object Injection in Ashtanga
CVE-2026-40751
CVE-2026-40739 - WordPress component
Unauthenticated PHP Object Injection in LuxeDrive
CVE-2026-40739
CVE-2026-40725 - WordPress component
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
CVE-2026-40725
CVE-2026-40726 - WordPress component
Unauthenticated Broken Access Control in User Registration Stripe
CVE-2026-40726
CVE-2026-40736 - WordPress component
Unauthenticated PHP Object Injection in Laurits
CVE-2026-40736
CVE-2026-40735 - WordPress component
Unauthenticated PHP Object Injection in Reina
CVE-2026-40735
CVE-2026-40731 - WordPress component
Unauthenticated Local File Inclusion in ChapterOne
CVE-2026-40731
CVE-2026-40724 - WordPress component
CP Client Arbitrary File Download in Client Portal (Pro)
CVE-2026-40724
CVE-2026-40722 - Yoast SEO Plugin
Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.
CVE-2026-40722
CVE-2026-40723 - WordPress component
Subscriber Broken Access Control in Bricks Builder
CVE-2026-40723
CVE-2026-40721 - WordPress component
Contributor Local File Inclusion in Element Pack Pro
CVE-2026-40721
CVE-2026-39598 - Academy LMS Pro Plugin
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
CVE-2026-39598
CVE-2026-39589 - WordPress component
Subscriber Arbitrary File Upload in Webenvo
CVE-2026-39589
CVE-2026-39596 - WordPress component
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
CVE-2026-39596
CVE-2026-39582 - WordPress component
Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
CVE-2026-39582
CVE-2026-39580 - WordPress component
Unauthenticated PHP Object Injection in Micdrop
CVE-2026-39580
CVE-2026-39597 - Elementor Plugin
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor
CVE-2026-39597
CVE-2026-39578 - WordPress component
Unauthenticated PHP Object Injection in Valiance
CVE-2026-39578
CVE-2026-39595 - WordPress component
Author Broken Access Control in W3 Total Cache
CVE-2026-39595
