Export limit exceeded: 404011 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404011 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93943 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0. | ||||
| CVE-2026-93942 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0. | ||||
| CVE-2026-93941 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2. | ||||
| CVE-2026-93940 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0. | ||||
| CVE-2026-93938 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7. | ||||
| CVE-2026-93937 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0. | ||||
| CVE-2026-93936 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4. | ||||
| CVE-2026-93935 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15. | ||||
| CVE-2026-93934 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13. | ||||
| CVE-2026-93933 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4. | ||||
| CVE-2026-93932 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12. | ||||
| CVE-2026-93931 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0. | ||||
| CVE-2026-93930 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0. | ||||
| CVE-2026-93929 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16. | ||||
| CVE-2026-93927 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0. | ||||
| CVE-2026-93950 | 2026-10-10 | 7.5 High | ||
| Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108. | ||||
| CVE-2026-93949 | 2026-10-10 | 7.1 High | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3. | ||||
| CVE-2026-106606 | 2026-10-10 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a through 3.31.0. | ||||
| CVE-2026-108503 | 2026-10-10 | 3.3 Low | ||
| ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information. | ||||
| CVE-2026-14335 | 2 Smub, Wordpress-extensions | 3 Easy Digital Downloads, Easy Digital Downloads – Ecommerce Payments And Subscriptions Made Easy, Easy Digital Downloads | 2026-10-10 | 7.2 High |
| The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||