NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3301 8.1 HIGH
Network
- - Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: … CWE-266
 Incorrect Privilege Assignment
CVE-2026-24373 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3302 8.1 HIGH
Network
- - Vulnerabilidad de Asignación Incorrecta de Privilegios en Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager permite escalada de privilegios. Este problema afecta a … CWE-266
 Incorrect Privilege Assignment
CVE-2026-24373 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3303 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPVulnerability: from … CWE-862
 Missing Authorization
CVE-2026-24376 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3304 6.5 MEDIUM
Network
- - Vulnerabilidad por falta de autorización en Javier Casares WPVulnerability wpvulnerability permite la explotación de niveles de seguridad de control de acceso mal configurados. Este problema afecta a… CWE-862
 Missing Authorization
CVE-2026-24376 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3305 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24378 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3306 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en Metagauss EventPrime eventprime-event-calendar-management permite la inyección de objetos. Este problema afecta a EventPrime: desde n/a has… CWE-502
 Deserialization of Untrusted Data
CVE-2026-24378 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3307 7.5 HIGH
Network
- - Missing Authorization vulnerability in wproyal News Magazine X news-magazine-x allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Magazine X: from n/a thr… CWE-862
 Missing Authorization
CVE-2026-24382 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3308 7.5 HIGH
Network
- - Vulnerabilidad de autorización faltante en wproyal News Magazine X news-magazine-x permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a News… CWE-862
 Missing Authorization
CVE-2026-24382 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3309 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeMakers Car Dealer cardealer allows Reflected XSS.This issue affects Car Dealer: from n/a thr… CWE-79
Cross-site Scripting
CVE-2026-24391 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3310 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeMakers Car Dealer cardealer permite XSS Reflejado. Este problema afecta a … CWE-79
Cross-site Scripting
CVE-2026-24391 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3311 6.4 MEDIUM
Network
- - Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-24964 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3312 6.4 MEDIUM
Network
- - Vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en Wasiliy Strecker / desarrollador de ContestGallery Contest Gallery contest-gallery permite la falsificación de petición del… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-24964 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3313 9.8 CRITICAL
Network
- - Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30. CWE-266
 Incorrect Privilege Assignment
CVE-2026-24968 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3314 9.8 CRITICAL
Network
- - Vulnerabilidad de Asignación Incorrecta de Privilegios en Xagio SEO Xagio SEO xagio-seo permite la escalada de privilegios. Este problema afecta a Xagio SEO: desde n/a hasta &lt;= 7.1.0.30. CWE-266
 Incorrect Privilege Assignment
CVE-2026-24968 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3315 7.7 HIGH
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a throu… CWE-22
Path Traversal
CVE-2026-24969 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3316 7.7 HIGH
Network
- - Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') vulnerabilidad en designingmedia Instant VA instantva permite Salto de Ruta. Este problema afecta a Instant VA… CWE-22
Path Traversal
CVE-2026-24969 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3317 7.7 HIGH
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.… CWE-22
Path Traversal
CVE-2026-24970 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3318 7.7 HIGH
Network
- - Vulnerabilidad de Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en designingmedia Energox energox permite Salto de Ruta. Este problema afecta a Energox: des… CWE-22
Path Traversal
CVE-2026-24970 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3319 9.8 CRITICAL
Network
- - Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8. CWE-266
 Incorrect Privilege Assignment
CVE-2026-24971 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3320 9.8 CRITICAL
Network
- - Vulnerabilidad de Asignación de Privilegios Incorrecta en Elated-Themes Search &amp; Go searchgo permite la escalada de privilegios. Este problema afecta a Search &amp; Go: desde n/a hasta &lt;= 2.8. CWE-266
 Incorrect Privilege Assignment
CVE-2026-24971 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3321 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a th… CWE-862
 Missing Authorization
CVE-2026-24972 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3322 6.5 MEDIUM
Network
- - Vulnerabilidad de Autorización faltante en Elated-Themes Elated Listing eltd-listing permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af… CWE-862
 Missing Authorization
CVE-2026-24972 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3323 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme CitiLights noo-citilights allows Reflected XSS.This issue affects CitiLights: from n/a t… CWE-79
Cross-site Scripting
CVE-2026-24973 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3324 7.1 HIGH
Network
- - Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme CitiLights noo-citilights permite XSS Reflejado. Este problema afecta a C… CWE-79
Cross-site Scripting
CVE-2026-24973 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3325 8.8 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <= 3.7.1. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24974 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3326 8.8 HIGH
Network
- - Deserialización de Datos No Confiables vulnerabilidad en NooTheme CitiLights noo-citilights permite Inyección de Objetos. Este problema afecta a CitiLights: desde n/a hasta &lt;= 3.7.1. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24974 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3327 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici L… CWE-79
Cross-site Scripting
CVE-2026-24975 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3328 7.1 HIGH
Network
- - Neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting') vulnerabilidad en la biblioteca NooTheme Organici noo-organici-library permite XSS reflejado. Est… CWE-79
Cross-site Scripting
CVE-2026-24975 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3329 8.8 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24976 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3330 8.8 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en NooTheme Organici Biblioteca noo-organici-library permite la inyección de objetos. Este problema afecta a Organici Biblioteca: desde n/a ha… CWE-502
 Deserialization of Untrusted Data
CVE-2026-24976 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3331 8.5 HIGH
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Orga… CWE-89
SQL Injection
CVE-2026-24977 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3332 8.5 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en la biblioteca Organici de NooTheme noo-organici-library permite Inyección SQL Cie… CWE-89
SQL Injection
CVE-2026-24977 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3333 8.8 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24978 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3334 8.8 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en NooTheme Jobica Core jobica-core permite la inyección de objetos. Este problema afecta a Jobica Core: desde n/a hasta &lt;= 1.4.1. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24978 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3335 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobica Core: from n/a th… CWE-79
Cross-site Scripting
CVE-2026-24979 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3336 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme Jobica Core jobica-core permite XSS Reflejado. Este problema afecta a … CWE-79
Cross-site Scripting
CVE-2026-24979 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3337 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue affects Visionary Core… CWE-79
Cross-site Scripting
CVE-2026-24980 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3338 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme Visionary Core noo-visionary-core permite XSS Reflejado. Este problema… CWE-79
Cross-site Scripting
CVE-2026-24980 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3339 8.8 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24981 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3340 8.8 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en NooTheme Visionary Core noo-visionary-core permite la inyección de objetos. Este problema afecta a Visionary Core: desde n/a hasta &lt;= 1.… CWE-502
 Deserialization of Untrusted Data
CVE-2026-24981 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3341 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from … CWE-79
Cross-site Scripting
CVE-2026-24983 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3342 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en UpSolution UpSolution Core us-core permite XSS Reflejado. Este problema afecta … CWE-79
Cross-site Scripting
CVE-2026-24983 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3343 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a thr… CWE-862
 Missing Authorization
CVE-2026-24987 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3344 6.5 MEDIUM
Network
- - Vulnerabilidad de autorización faltante en activity-log.com WP System Log winterlock permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af… CWE-862
 Missing Authorization
CVE-2026-24987 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3345 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0. CWE-502
 Deserialization of Untrusted Data
CVE-2026-24989 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3346 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en FantasticPlugins SUMO Affiliates Pro affs permite la inyección de objetos. Este problema afecta a SUMO Affiliates Pro: desde n/a hasta &lt;… CWE-502
 Deserialization of Untrusted Data
CVE-2026-24989 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3347 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statis… CWE-89
SQL Injection
CVE-2026-24993 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3348 9.3 CRITICAL
Network
- - Neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') vulnerabilidad en WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-rep… CWE-89
SQL Injection
CVE-2026-24993 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3349 8.5 HIGH
Network
- - Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.… CWE-94
Code Injection
CVE-2026-25001 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3350 8.5 HIGH
Network
- - Vulnerabilidad de control inadecuado de la generación de código ('Inyección de Código') en Saad Iqbal Post Snippets post-snippets permite la Inclusión Remota de Código. Este problema afecta a Post Sn… CWE-94
Code Injection
CVE-2026-25001 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm