CVEs we hold for The
Records whose assigning authority named The as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9832Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature…themehigh Payment Gateway of Stripe for WooCommerce
CVE-2026-92465WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerabilityThemeum WP Mega Menu
CVE-2026-9018Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via…themewant Easy Elements for Elementor – Addons & Website…
CVE-2026-8976RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2026-89333Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via…themeum Tutor LMS – eLearning and online course solution
CVE-2026-89089OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)The OpenNMS Group Horizon
CVE-2026-89081Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parametersthemeum Tutor LMS – eLearning and online course solution
CVE-2026-89054OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changesThe OpenNMS Group Horizon
CVE-2026-89023ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST APIThemeAtelier Domain For Sale
CVE-2026-88944Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id'…themeum Tutor LMS – eLearning and online course solution
CVE-2026-8713Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Valuethemefusion Avada (Fusion) Builder
CVE-2026-8689Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+)…themeisle Visualizer: Tables and Charts Manager for…
CVE-2026-8674Assertion failure in the DNS stub resolver with a long search domainThe GNU C Library glibc
CVE-2026-86434commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collisionthephpleague commonmark
CVE-2026-86431commonmark before 2.9.1 XSS via AttributesExtension form feed bypassthephpleague commonmark
CVE-2026-86429commonmark before 2.9.1 Denial of Service via SmartPunct and Attributesthephpleague commonmark
CVE-2026-86428commonmark 1.5.0 before 2.10.0 Denial of Service via Attributesthephpleague commonmark
CVE-2026-85691MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/urlThe-Vibe-Company megaparse
CVE-2026-85455MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packetthemoos core-moos
CVE-2026-85454MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handlingthemoos core-moos
CVE-2026-85453MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scriptingthemoos core-moos
CVE-2026-85452MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiersthemoos ui-moos
CVE-2026-85451MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphrasethemoos core-moos
CVE-2026-85442MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocationthemoos core-moos
CVE-2026-85441MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Lengththemoos core-moos
CVE-2026-85440MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Lengththemoos core-moos
CVE-2026-85436MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Lengththemoos essential-moos
CVE-2026-85433MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfigurationthemoos essential-moos
CVE-2026-85432MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identitythemoos core-moos
CVE-2026-85431MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injectionthemoos essential-moos
CVE-2026-85430MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishingthemoos essential-moos
CVE-2026-85428MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Writethemoos core-moos
CVE-2026-85427MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILEthemoos essential-moos
CVE-2026-85424MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEARthemoos core-moos
CVE-2026-85198MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Paththemeisle MPG – Multiple Page Generator, Bulk Landing Pages…
CVE-2026-84745The Events Calendar < 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST APIUnknown The Events Calendar
CVE-2026-8369Improper Input Validation in OpenThread NAT64 TranslatorThe OpenThread Authors OpenThread
CVE-2026-8358Heap buffer overflow in spreadsheet tracked-changes importThe Document Foundation LibreOffice
CVE-2026-8206Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'themeum Kirki – Freeform Page Builder, Website Builder &…
CVE-2026-81785WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerabilityThemekraft BuddyForms
CVE-2026-81778WordPress Kalles Addons plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerabilityThe4 Kalles Addons
CVE-2026-81583Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege EscalationUnknown Theme My Login
CVE-2026-8096Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via…themeum Kirki – Freeform Page Builder, Website Builder &…
CVE-2026-8073Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIPthemeum Kirki – Freeform Page Builder, Website Builder &…
CVE-2026-78290WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerabilityThemeGrill Magazine Blocks
CVE-2026-78175Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Executionthemeum Tutor LMS – eLearning and online course solution
CVE-2026-78172Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scriptingthemifyme Themify – WooCommerce Product Filter
CVE-2026-75027Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via…themifyme Themify Builder
CVE-2026-74018WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerabilitythemagnifico52 Warehouse Cargo
CVE-2026-74016WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerabilitythemagnifico52 Smart Cleaning
CVE-2026-73389WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerabilityThe4 Kalles Addons
CVE-2026-73347WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerabilityThemetechMount TrueBooker
CVE-2026-7330Auto Affiliate Links <= 6.8.8 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameterthedark Auto Affiliate Links
CVE-2026-73189WordPress WP Crowdfunding plugin < 2.2.1 - Insecure Direct Object References (IDOR) vulnerabilityThemeum WP Crowdfunding
CVE-2026-73181WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbitrary File Download vulnerabilityThemeComplete Extra Product Options & Add-Ons for…
CVE-2026-7284Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_registerthemewant Easy Elements for Elementor – Addons & Website…
CVE-2026-71488league/commonmark: Quadratic-time denial of service when parsing crafted Markdownthephpleague commonmark
CVE-2026-71478league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytesthephpleague commonmark
CVE-2026-71231IOTSmartHome - Unauthenticated SQL Injection via lastLogin Cookiethebradleysanders IOTSmartHome
CVE-2026-70378imagecli - Negative carve Ratio Bypasses Bounds Check and Crashes Process via Reachable Panictheotherphil imagecli
CVE-2026-70377imagecli - Uncontrolled Memory Allocation via Unbounded scale Ratio Causes Denial of Servicetheotherphil imagecli
CVE-2026-6965Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via…themeum Tutor LMS – eLearning and online course solution
CVE-2026-6791Potential stack-based buffer clash during tilde expansion in wordexpThe GNU C Library glibc
CVE-2026-66652WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Tour
CVE-2026-66650WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerabilityTheme-Rex FreightCo
CVE-2026-6663GWD Connect <= 2.9 - Unauthenticated Limited Code Execution via update_agentthewebsitesupply GWD Conex
CVE-2026-66629WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerabilityThemeum Kirki
CVE-2026-66607WordPress Advance Product Search plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerabilityThemeHunk Advance Product Search
CVE-2026-66606WordPress SmartSMTP plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerabilityThemeGrill SmartSMTP
CVE-2026-66586WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerabilityThemewinter WP Cafe Pro
CVE-2026-66471WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerabilityThemepoints Accordion
CVE-2026-66437WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerabilityThemeisle Feedzy
CVE-2026-65563WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerabilityThemeIsle
CVE-2026-65537WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control…Themeisle Cyr to Lat reloaded – transliteration of links…
CVE-2026-65526WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerabilityThemeisle Visualizer
CVE-2026-65524WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerabilityThemeFusion Avada Custom Branding
CVE-2026-65487WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerabilityThemeGoods Photography
CVE-2026-65439WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerabilityThemefic Ultimate Addons for Contact Form 7
CVE-2026-65433WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control…themewant RT Mega Menu – Mega Menu Builder for Elementor…
CVE-2026-63099TheHive 4.1.24 Broken Object Level Authorization via Attachment Download EndpointsTheHive-Project TheHive
CVE-2026-63098TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status EndpointTheHive-Project TheHive
CVE-2026-6279Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics'…themefusion Avada (Fusion) Builder
CVE-2026-62105WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerabilityThemeREX Addons
CVE-2026-61970WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerabilityThemeisle Auto Featured Image (Auto Post Thumbnail)
CVE-2026-61960WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerabilityThemeisle WP Full Stripe Free
CVE-2026-61951WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerabilitythemetechmount TrueBooker
CVE-2026-61950WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerabilitythemetechmount TrueBooker
CVE-2026-6080Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameterthemeum Tutor LMS – eLearning and online course solution
CVE-2026-6047Heap buffer overflow in OOXML text box element importThe Document Foundation LibreOffice
CVE-2026-6040Heap use-after-free in ODF number-format blank-width parsingThe Document Foundation LibreOffice
CVE-2026-60034Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0themexpert.com JMedia extension for Joomla
CVE-2026-60033Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0themexpert.com JMedia extension for Joomla
CVE-2026-60032Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0themexpert.com JMedia extension for Joomla
CVE-2026-60031Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60030Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60029Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60028Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60027Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-60026Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-59559WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS)…themewant RT Mega Menu – Mega Menu Builder for Elementor…
CVE-2026-58521SQLi in Cargo extension via year range filterThe Wikimedia Foundation Mediawiki - Cargo Extension
CVE-2026-58520UrlShortener defaults to ineffective validation open to third-party redirectsThe Wikimedia Foundation Mediawiki - UrlShortener Extension
CVE-2026-58519Stored XSS through Cargo's map formatThe Wikimedia Foundation Mediawiki - Cargo Extension
CVE-2026-58517Blocked users can create and edit WikiLambda objectsThe Wikimedia Foundation Mediawiki - WikiLambda Extension
CVE-2026-58078Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1themexpert.com Quix Page Builder Pro extension for Joomla
CVE-2026-57843NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information DisclosureThe NetBSD Foundation NetBSD
CVE-2026-57842NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlenThe NetBSD Foundation NetBSD
CVE-2026-57797WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerabilityThemeMove EduMall
CVE-2026-57795WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerabilitythemelexus Kitchor
CVE-2026-57779WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerabilitythemebeez Fascinate
CVE-2026-57770WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerabilityThemeGoods Grand Photography
CVE-2026-57769WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Photography
CVE-2026-57749WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerabilityThemeBoy SportsPress Pro
CVE-2026-57747WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerabilityThemeREX Booked
CVE-2026-57725WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerabilityThemeum Kirki
CVE-2026-57694WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerabilityThemeum Tutor LMS
CVE-2026-57680WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerabilityThemeum Kirki
CVE-2026-57678WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerabilityThemePunch Slider Revolution
CVE-2026-57627WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnerabilityThemeum Kirki
CVE-2026-57618WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerabilityThemeisle Neve PRO
CVE-2026-57405WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerabilitythemehunk Open Shop
CVE-2026-57395WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerabilityThemefic Tourfic
CVE-2026-57392WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerabilityThemefic Tourfic
CVE-2026-57388WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerabilityThemefic Hydra Booking
CVE-2026-57369WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulnerabilitythemifyme Themify Builder
CVE-2026-56070WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerabilityThemeHunk Advance Product Search
CVE-2026-56058WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerabilityThemeCatcher Quform
CVE-2026-56050WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityThemeisle PPOM for WooCommerce
CVE-2026-56037WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerabilityThemify Popup
CVE-2026-56028WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation vulnerabilitythemewant Easy Elements for Elementor – Addons &…
CVE-2026-56008WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerabilityThemeFusion Fusion Builder
CVE-2026-55747PocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File ToolsThe-Pocket PocketFlow (pocketflow-coding-agent cookbook…
CVE-2026-5508WowPress <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributestheyeti WowPress
CVE-2026-5502Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via…themeum Tutor LMS – eLearning and online course solution
CVE-2026-54807WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerabilityThemeGrill Registration Form for WooCommerce
CVE-2026-54334UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen`theopolis uefi-firmware-parser
CVE-2026-54333UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTabletheopolis uefi-firmware-parser
CVE-2026-54194WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerabilityThemeFusion Fusion Builder
CVE-2026-54193WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabilityThemeFusion Fusion Builder
CVE-2026-53996NetBSD hdaudio(4) Driver Privilege Bypass Use-After-Free via HDAUDIO_FGRP_SETCONFIG ioctlThe NetBSD Foundation NetBSD
CVE-2026-5324Brizy – Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Valuethemefusecom Brizy – Page Builder
CVE-2026-52701WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerabilityThemegrill User Registration
CVE-2026-50722IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payloadThe Libreswan Project libreswan
CVE-2026-50721IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payloadThe Libreswan Project libreswan
CVE-2026-4945Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypassthemeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2026-49248OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via…theonedev onedev
CVE-2026-49113WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerabilityTHEMECO Cornerstone
CVE-2026-49111WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerabilityThemeGrill Masteriyo - LMS
CVE-2026-49081WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control vulnerabilityThemeGrill User Registration Stripe
CVE-2026-48881WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerabilitythemetechmount TrueBooker
CVE-2026-4804Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST APIthemegrill Zakra
CVE-2026-4798Avada Builder <= 3.15.1 - Unauthenticated SQL Injection via 'product_order' Parameterthemefusion Avada (Fusion) Builder
CVE-2026-4782Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameterthemefusion Avada (Fusion) Builder
CVE-2026-45217WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerabilityThemeHigh Stripe Payment Gateway for WooCommerce
CVE-2026-44647OneDev: Path Traversal (read capability via Git LFS pointer resolution)theonedev onedev
CVE-2026-4437gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS responseThe GNU C Library glibc
CVE-2026-4431Easy Post Submission <= 2.3.0 - Missing Authorizationthemeruby Easy Post Submission – Frontend Posting, Guest…
CVE-2026-42749WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerabilityThemeisle Disable Comments for Any Post Types (Remove…
CVE-2026-42743WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerabilityThemeGrill Masteriyo - LMS
CVE-2026-42675WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerabilityThemefic Hydra Booking
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.