Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-27438 Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27437 Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27417 Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27389 Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-book… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.0 CVE-2026-27384 Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properl… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-24960 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-23802 Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI En… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-23767 ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not… Sb H50 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22501 Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a thr… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22497 Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22475 Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22474 Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22454 Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22453 Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22451 Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-22417 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: fr… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-22390 Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allo… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.3 CVE-2025-69338 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode Core riode-core allows Blind S… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2025-68555 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affect… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2025-68554 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarc… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2025-68553 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affect… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-54001 Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2024-57854 Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead… Net\ after 0.009002 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib libra… Compress\ after 2.219 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-3257 UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Ver… Unqlite 0.07+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2025-40931 Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insec… Apache\ after 1.94 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-40926 Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 … Plack\ 0.05+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-2835 An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs du… Pingora 0.8.0+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-2833 An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora pr… Pingora 0.8.0+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-29045 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with r… Hono 4.12.4+ Fix from $2,3002026-03-04