Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51667
Total
4097
Critical
15338
High
14987
Medium
CVE ID Severity Score Description Published
CVE-2026-61973 MEDIUM 4.3 Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. Jul 23, 2026
CVE-2026-61972 MEDIUM 5.3 Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. Jul 23, 2026
CVE-2026-61954 HIGH 7.5 Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. Jul 23, 2026
CVE-2026-61951 CRITICAL 9.8 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. Jul 23, 2026
CVE-2026-61950 CRITICAL 9.3 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. Jul 23, 2026
CVE-2026-61949 CRITICAL 9.3 Unauthenticated SQL Injection in Bookly <= 27.7 versions. Jul 23, 2026
CVE-2026-61948 CRITICAL 9.3 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. Jul 23, 2026
CVE-2026-61947 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. Jul 23, 2026
CVE-2026-61946 MEDIUM 6.5 Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. Jul 23, 2026
CVE-2026-61945 MEDIUM 6.5 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects … Jul 23, 2026
CVE-2026-61944 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. Jul 23, 2026
CVE-2026-61943 HIGH 7.5 Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. Jul 23, 2026
CVE-2026-59555 CRITICAL 10.0 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. Jul 23, 2026
CVE-2026-59554 HIGH 7.5 Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. Jul 23, 2026
CVE-2026-59547 HIGH 7.5 Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. Jul 23, 2026
CVE-2026-59545 HIGH 8.1 Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. Jul 23, 2026
CVE-2026-59544 CRITICAL 9.8 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. Jul 23, 2026
CVE-2026-59543 CRITICAL 9.9 Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. Jul 23, 2026
CVE-2026-59542 HIGH 7.7 Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. Jul 23, 2026
CVE-2026-59541 HIGH 8.8 Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. Jul 23, 2026
CVE-2026-59540 CRITICAL 9.8 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. Jul 23, 2026
CVE-2026-59526 CRITICAL 9.3 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. Jul 23, 2026
CVE-2026-59525 CRITICAL 9.3 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. Jul 23, 2026
CVE-2026-59524 MEDIUM 6.5 Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. Jul 23, 2026
CVE-2026-59522 MEDIUM 6.5 Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. Jul 23, 2026