Vulnerability index

Browse CVEs

1,269 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 8.1 CVE-2026-22515 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegada… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22502 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mr. Cobbler mr-… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22503 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Nelson nelson allow… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22504 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22506 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Amoli amoli al… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22493 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gaspard gaspar… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22494 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Good Homes good-hom… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22495 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Greenville gree… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22496 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hypnotherapy hy… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22498 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent lauren… Mitigation only Fix from $1,9502026-03-25 HIGH 8.1 CVE-2026-22499 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Lella lella al… Mitigation only Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-33513 WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates u… Avideo after 26.0 Fix from $1,9502026-03-23 MEDIUM 6.5 CVE-2026-33130 Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to … Uptime Kuma 2.2.1+ Fix from $1,6002026-03-20 HIGH 8.1 CVE-2026-22324 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP … Mitigation only Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-27065 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress build… Mitigation only Fix from $2,3002026-03-19 HIGH 8.1 CVE-2026-27093 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Tripgo tripgo allow… Mitigation only Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-29858 A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure. Aapanel No fix yet Fix from $1,9502026-03-18 HIGH 8.8 CVE-2026-1463 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a… Mitigation only Fix from $1,9502026-03-18 HIGH 8.8 CVE-2026-27894 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.… Ldap Account Manager 9.5+ Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-32426 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core me… Mitigation only Fix from $1,9502026-03-13 HIGH 7.2 CVE-2026-32401 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-32400 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemetechMount Boldman boldm… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-32392 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly gre… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-32393 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly The… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-32384 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly s… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-32369 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core me… Mitigation only Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-32364 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo… Mitigation only Fix from $1,9502026-03-13 CRITICAL 9.8 CVE-2026-3826 IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the se… Organization Portal System Mitigation only Fix from $2,3002026-03-11 HIGH 8.1 CVE-2026-28123 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allow… Mitigation only Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-28124 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Notarius notari… Mitigation only Fix from $1,9502026-03-05