NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2801 8.8 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32484 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2802 8.8 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en BoldGrid weForms weforms permite la inyección de objetos. Este problema afecta a weForms: desde n/a hasta &lt;= 1.6.26. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32484 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2803 7.5 HIGH
Network
- - Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a t… CWE-862
 Missing Authorization
CVE-2026-32485 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2804 7.5 HIGH
Network
- - Vulnerabilidad por ausencia de autorización en weDevs WP User Frontend wp-user-frontend permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a… CWE-862
 Missing Authorization
CVE-2026-32485 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2805 8.1 HIGH
Network
- - Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9. CWE-266
 Incorrect Privilege Assignment
CVE-2026-32488 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2806 8.1 HIGH
Network
- - Vulnerabilidad de Asignación Incorrecta de Privilegios en wpeverest User Registration user-registration permite la escalada de privilegios. Este problema afecta a User Registration: desde n/a hasta &… CWE-266
 Incorrect Privilege Assignment
CVE-2026-32488 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2807 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30. CWE-862
 Missing Authorization
CVE-2026-32489 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2808 6.5 MEDIUM
Network
- - Vulnerabilidad de Autorización Faltante en bPlugins B Blocks b-blocks permite la Explotación de Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a B Blocks… CWE-862
 Missing Authorization
CVE-2026-32489 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2809 6.5 MEDIUM
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider allows Stored XSS.This issue … CWE-79
Cross-site Scripting
CVE-2026-32490 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2810 6.5 MEDIUM
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider permite XSS… CWE-79
Cross-site Scripting
CVE-2026-32490 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2811 6.5 MEDIUM
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Review Slider wp-facebook-reviews allows Stored XSS.This issue affects WP Review Sli… CWE-79
Cross-site Scripting
CVE-2026-32491 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2812 6.5 MEDIUM
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en jgwhite33 WP Review Slider wp-facebook-reviews permite XSS Almacenado. Este pro… CWE-79
Cross-site Scripting
CVE-2026-32491 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2813 5.3 MEDIUM
Network
- - Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1. CWE-290
 Authentication Bypass by Spoofing
CVE-2026-32492 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2814 5.3 MEDIUM
Network
- - Vulnerabilidad de omisión de autenticación por suplantación en Joe Dolson My Tickets my-tickets permite la suplantación de identidad. Este problema afecta a My Tickets: desde n/a hasta &lt;= 2.1.1. CWE-290
 Authentication Bypass by Spoofing
CVE-2026-32492 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2815 - -
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through… CWE-79
Cross-site Scripting
CVE-2026-32493 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2816 - -
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en eyecix JobSearch wp-jobsearch permite XSS Reflejado. Este problema afecta a Job… CWE-79
Cross-site Scripting
CVE-2026-32493 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2817 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Se… CWE-79
Cross-site Scripting
CVE-2026-32494 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2818 7.1 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('Cross-site Scripting') en Ays Pro Image Slider de Ays ays-slider permite la Explotación de Niveles de … CWE-79
Cross-site Scripting
CVE-2026-32494 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2819 7.5 HIGH
Network
- - Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Terms Popup: from … CWE-862
 Missing Authorization
CVE-2026-32495 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2820 7.5 HIGH
Network
- - Vulnerabilidad de autorización faltante en Link Software LLC WP Terms Popup wp-terms-popup permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este probl… CWE-862
 Missing Authorization
CVE-2026-32495 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2821 6.7 MEDIUM
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-7-spam-blocker allows Path Traversal.This issue af… CWE-22
Path Traversal
CVE-2026-32496 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2822 6.7 MEDIUM
Network
- - Vulnerabilidad de limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') en NYSL Spam Protect para Contact Form 7 wp-contact-form-7-spam-blocker permite el salto de … CWE-22
Path Traversal
CVE-2026-32496 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2823 5.3 MEDIUM
Network
- - Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45. CWE-1390
 Weak Authentication
CVE-2026-32497 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2824 5.3 MEDIUM
Network
- - Vulnerabilidad de autenticación débil en PickPlugins User Verification user-verification permite el abuso de autenticación. Este problema afecta a User Verification: desde n/a hasta &lt;= 2.0.45. CWE-1390
 Weak Authentication
CVE-2026-32497 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2825 7.5 HIGH
Network
- - Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… CWE-862
 Missing Authorization
CVE-2026-32498 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2826 7.5 HIGH
Network
- - Vulnerabilidad de Falta de Autorización en Metagauss RegistrationMagic constructor de formularios de registro personalizados con gestor de envíos permite Explotar Niveles de Seguridad de Control de A… CWE-862
 Missing Authorization
CVE-2026-32498 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2827 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a thro… CWE-89
SQL Injection
CVE-2026-32499 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2828 9.3 CRITICAL
Network
- - La vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en el chatbot QuantumCloud ChatBot permite Inyección SQL Ciega. Este problema afe… CWE-89
SQL Injection
CVE-2026-32499 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2829 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS MetaMax metamax allows PHP Local File Inclusion.This issue affects … CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32500 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2830 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') vulnerabilidad en CreativeWS MetaMax metamax permite la Inclusión … CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32500 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2831 7.1 HIGH
Network
- - Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Configurat… CWE-862
 Missing Authorization
CVE-2026-32501 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2832 7.1 HIGH
Network
- - Vulnerabilidad de autorización faltante en wp-configurator WP Configurator Pro wp-configurator-pro permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este proble… CWE-862
 Missing Authorization
CVE-2026-32501 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2833 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32502 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2834 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en Select-Themes Borgholm borgholm-marketing-agency-theme permite la inyección de objetos. Este problema afecta a Borgholm: desde n/a hasta &l… CWE-502
 Deserialization of Untrusted Data
CVE-2026-32502 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2835 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Trendustry trendustry allows PHP Local File Inclusion.This issue af… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32503 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2836 8.1 HIGH
Network
- - Vulnerabilidad de control inadecuado del nombre de fichero para la declaración include/require en el programa PHP ('inclusión remota de ficheros PHP') en CreativeWS Trendustry trendustry permite la i… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32503 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2837 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS VintWood vintwood allows PHP Local File Inclusion.This issue affect… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32504 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2838 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP (vulnerabilidad de 'Inclusión remota de ficheros PHP') en CreativeWS VintWood vintwood permite la Inclu… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32504 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2839 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Kiddy kiddy allows PHP Local File Inclusion.This issue affects Kidd… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32505 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2840 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en CreativeWS Kiddy kiddy permite la inclusión l… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-32505 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2841 5.4 MEDIUM
Network
- - Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32506 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2842 5.4 MEDIUM
Network
- - Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Archicon archicon permite la inyección de objetos. Este problema afecta a Archicon: desde n/a hasta &lt; 1.7. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32506 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2843 5.4 MEDIUM
Network
- - Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32507 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2844 5.4 MEDIUM
Network
- - Vulnerabilidad de deserialización de datos no confiables en Elated-Themes Leroux leroux permite la inyección de objetos. Este problema afecta a Leroux: desde n/a hasta &lt; 1.4. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32507 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2845 5.4 MEDIUM
Network
- - Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32508 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2846 5.4 MEDIUM
Network
- - Vulnerabilidad de deserialización de datos no confiables en Mikado-Themes Halstein halstein permite la inyección de objetos. Este problema afecta a Halstein: desde n/a hasta &lt; 1.8. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32508 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2847 5.4 MEDIUM
Network
- - Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32509 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2848 5.4 MEDIUM
Network
- - Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Gracey gracey permite la inyección de objetos. Este problema afecta a Gracey: desde n/a hasta &lt; 1.4. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32509 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2849 5.4 MEDIUM
Network
- - Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a through < 1.3. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32510 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2850 5.4 MEDIUM
Network
- - Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Kamperen kamperen permite la inyección de objetos. Este problema afecta a Kamperen: desde n/d hasta &lt; 1.3. CWE-502
 Deserialization of Untrusted Data
CVE-2026-32510 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm