NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3201 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion.This issue affect… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22504 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3202 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') vulnerabilidad en ThemeREX ProLingua prolingua permite la Inclusió… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22504 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3203 8.1 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Records: from n/a through <= 1.2. CWE-502
 Deserialization of Untrusted Data
CVE-2026-22505 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3204 8.1 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en AncoraThemes Morning Records morning-records permite la inyección de objetos. Este problema afecta a Morning Records: desde n/a hasta &lt;=… CWE-502
 Deserialization of Untrusted Data
CVE-2026-22505 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3205 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Amoli amoli allows PHP Local File Inclusion.This issue affects A… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22506 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3206 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP, vulnerabilidad de 'Inclusión remota de ficheros PHP', en Elated-Themes Amoli amoli permite la inclusió… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22506 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3207 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6. CWE-502
 Deserialization of Untrusted Data
CVE-2026-22507 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3208 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en AncoraThemes Beelove beelove permite la inyección de objetos. Este problema afecta a Beelove: desde n/a hasta &lt;= 1.2.6. CWE-502
 Deserialization of Untrusted Data
CVE-2026-22507 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3209 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Dentalux dentalux allows PHP Local File Inclusion.This issue affe… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22508 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3210 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP (vulnerabilidad 'Inclusión Remota de Ficheros PHP') en AncoraThemes Dentalux dentalux permite la Inclus… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22508 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3211 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gioia gioia allows PHP Local File Inclusion.This issue affects G… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22509 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3212 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en programa PHP, vulnerabilidad de 'inclusión remota de ficheros PHP' en Elated-Themes Gioia gioia permite la inclusión lo… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22509 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3213 8.1 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue affects Melody: from n/a through <= 1.6.3. CWE-502
 Deserialization of Untrusted Data
CVE-2026-22510 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3214 8.1 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en AncoraThemes Melody melodyschool permite la inyección de objetos. Este problema afecta a Melody: desde n/a hasta &lt;= 1.6.3. CWE-502
 Deserialization of Untrusted Data
CVE-2026-22510 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3215 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes NeoBeat neobeat allows PHP Local File Inclusion.This issue affec… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22511 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3216 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP ('Inclusión Remota de Ficheros PHP') vulnerabilidad en Elated-Themes NeoBeat neobeat permite la Inclusi… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22511 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3217 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Roisin roisin allows PHP Local File Inclusion.This issue affects… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22512 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3218 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP (vulnerabilidad de 'inclusión remota de ficheros' de PHP) en Elated-Themes Roisin roisin permite la inc… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22512 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3219 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Triompher triompher allows PHP Local File Inclusion.This issue af… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22513 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3220 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP, vulnerabilidad ('Inclusión remota de ficheros PHP') en AncoraThemes Triompher triompher permite la inc… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22513 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3221 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Unica unica allows PHP Local File Inclusion.This issue affects Un… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22514 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3222 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP, vulnerabilidad ('inclusión remota de ficheros PHP') en AncoraThemes Unica unica permite la inclusión l… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22514 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3223 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows PHP Local File Inclusion.This issue affe… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22515 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3224 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') vulnerabilidad en AncoraThemes VegaDays vegadays permite la Inclus… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22515 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3225 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wizor's wizors-investments allows PHP Local File Inclusion.This i… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22516 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3226 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP, la vulnerabilidad de 'inclusión remota de ficheros de PHP' en AncoraThemes Wizor's wizors-investments … CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-22516 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3227 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework allows Reflected XSS.This issue affects Handmade Fr… CWE-79
Cross-site Scripting
CVE-2026-22520 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3228 7.1 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en G5Theme Handmade Framework handmade-framework permite XSS Reflejado. Este pr… CWE-79
Cross-site Scripting
CVE-2026-22520 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3229 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra Word… CWE-79
Cross-site Scripting
CVE-2026-22523 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3230 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en themepassion Ultra WordPress Admin ultra-admin permite XSS Reflejado. Este prob… CWE-79
Cross-site Scripting
CVE-2026-22523 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3231 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows Reflected XSS.This issue affects Legacy Admin: from… CWE-79
Cross-site Scripting
CVE-2026-22524 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3232 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en themepassion Legacy Admin legacy-admin permite XSS Reflejado. Este problema afe… CWE-79
Cross-site Scripting
CVE-2026-22524 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3233 7.5 HIGH
Network
- - Missing Authorization vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Jobs for Wor… CWE-862
 Missing Authorization
CVE-2026-23806 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3234 7.5 HIGH
Network
- - Vulnerabilidad por falta de autorización en las publicaciones de empleo de BlueGlass Interactive AG Jobs for WordPress permite explotar niveles de seguridad de control de acceso configurados incorrec… CWE-862
 Missing Authorization
CVE-2026-23806 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3235 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Reflected XSS.This issue affec… CWE-79
Cross-site Scripting
CVE-2026-23807 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3236 7.1 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en WP Socio WP Telegram Widget and Join Link wptelegram-widget permite XSS Refl… CWE-79
Cross-site Scripting
CVE-2026-23807 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3237 8.1 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8. CWE-502
 Deserialization of Untrusted Data
CVE-2026-23971 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3238 8.1 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en xtemos WoodMart woodmart permite la inyección de objetos. Este problema afecta a WoodMart: desde n/a hasta &lt;= 8.3.8. CWE-502
 Deserialization of Untrusted Data
CVE-2026-23971 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3239 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.Thi… CWE-862
 Missing Authorization
CVE-2026-23972 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3240 6.5 MEDIUM
Network
- - Vulnerabilidad por falta de autorización en magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce permite explotar niveles de seguridad de control de acceso configurado… CWE-862
 Missing Authorization
CVE-2026-23972 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3241 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5. CWE-79
Cross-site Scripting
CVE-2026-23973 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3242 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en uxper Golo golo permite XSS Reflejado. Este problema afecta a Golo: desde n/a h… CWE-79
Cross-site Scripting
CVE-2026-23973 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3243 7.5 HIGH
Network
- - Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security … CWE-862
 Missing Authorization
CVE-2026-23977 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3244 7.5 HIGH
Network
- - Vulnerabilidad de autorización faltante en WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce permite la explotación de niveles de seguridad de control de … CWE-862
 Missing Authorization
CVE-2026-23977 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3245 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softwebmedia Gyan Elements gyan-elements allows Reflected XSS.This issue affects Gyan Elements: f… CWE-79
Cross-site Scripting
CVE-2026-23979 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3246 7.1 HIGH
Network
- - Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Softwebmedia Gyan Elements gyan-elements permite XSS Reflejado. Este problema afec… CWE-79
Cross-site Scripting
CVE-2026-23979 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3247 8.8 HIGH
Network
- - Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4. CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-24359 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3248 8.8 HIGH
Network
- - Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en Dokan, Inc. Dokan dokan-lite permite el abuso de autenticación. Este problema afecta a Dokan: desde n/a hasta &lt;= 4… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-24359 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3249 6.4 MEDIUM
Network
- - Missing Authorization vulnerability in bdthemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from … CWE-862
 Missing Authorization
CVE-2026-24362 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3250 6.4 MEDIUM
Network
- - Vulnerabilidad de Autorización Faltante en bdthemes Ultimate Post Kit ultimate-post-kit permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a… CWE-862
 Missing Authorization
CVE-2026-24362 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm