NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3351 7.5 HIGH
Network
- - Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-25002 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3352 7.5 HIGH
Network
- - Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en ThimPress LearnPress – Sepay Payment learnpress-sepay-payment permite el abuso de autenticación. Este problema afecta… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-25002 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3353 8.5 HIGH
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Bl… CWE-89
SQL Injection
CVE-2026-25007 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3354 8.5 HIGH
Network
- - Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-ele… CWE-89
SQL Injection
CVE-2026-25007 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3355 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Zone: from n/a thro… CWE-862
 Missing Authorization
CVE-2026-25009 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3356 6.5 MEDIUM
Network
- - Vulnerabilidad de autorización faltante en raratheme Education Zone education-zone permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afec… CWE-862
 Missing Authorization
CVE-2026-25009 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3357 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a th… CWE-79
Cross-site Scripting
CVE-2026-25013 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3358 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en WHMCSdes Phox Hosting phox-host permite XSS Reflejado. Este problema afecta a P… CWE-79
Cross-site Scripting
CVE-2026-25013 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3359 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows PHP Local File Inclu… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25017 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3360 8.1 HIGH
Network
- - La vulnerabilidad de control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión remota de ficheros PHP') en stmcan NaturaLife Extensions naturalife-ex… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25017 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3361 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects Natura… CWE-79
Cross-site Scripting
CVE-2026-25018 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3362 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en stmcan NaturaLife Extensions naturalife-extensions permite XSS Reflejado. Este … CWE-79
Cross-site Scripting
CVE-2026-25018 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3363 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: fr… CWE-79
Cross-site Scripting
CVE-2026-25025 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3364 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en e4jvikwp VikRestaurants vikrestaurants permite XSS Reflejado. Este problema afe… CWE-79
Cross-site Scripting
CVE-2026-25025 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3365 7.5 HIGH
Network
- - Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11. CWE-862
 Missing Authorization
CVE-2026-25026 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3366 7.5 HIGH
Network
- - Vulnerabilidad de Autorización Faltante en RadiusTheme Team tlp-team permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a Team: desde n/a ha… CWE-862
 Missing Authorization
CVE-2026-25026 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3367 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25029 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3368 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en park_of_ideas KIDZ kidz permite la inyección de objetos. Este problema afecta a KIDZ: desde n/a hasta &lt;= 5.24. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25029 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3369 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25030 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3370 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en park_of_ideas Goldish goldish permite Inyección de objetos. Este problema afecta a Goldish: desde n/a hasta &lt; 3.47. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25030 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3371 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25031 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3372 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en park_of_ideas Tasty Daily tastydaily permite la inyección de objetos. Este problema afecta a Tasty Daily: desde n/a hasta &lt; 1.27. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25031 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3373 9.8 CRITICAL
Network
- - Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25032 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3374 9.8 CRITICAL
Network
- - Vulnerabilidad de deserialización de datos no confiables en park_of_ideas Ricky ricky permite la inyección de objetos. Este problema afecta a Ricky: desde n/a hasta &lt; 2.31. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25032 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3375 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uixthemes Motta Addons motta-addons allows Reflected XSS.This issue affects Motta Addons: from n/… CWE-79
Cross-site Scripting
CVE-2026-25033 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3376 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en uixthemes Motta Addons motta-addons permite XSS Reflejado. Este problema afecta… CWE-79
Cross-site Scripting
CVE-2026-25033 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3377 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: fr… CWE-862
 Missing Authorization
CVE-2026-25034 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3378 6.5 MEDIUM
Network
- - Vulnerabilidad de autorización faltante en Iqonic Design KiviCare kivicare-clinic-management-system permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. E… CWE-862
 Missing Authorization
CVE-2026-25034 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3379 9.8 CRITICAL
Network
- - Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Co… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-25035 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3380 9.8 CRITICAL
Network
- - Omisión de autenticación Usando una Ruta o Canal Alternativo vulnerabilidad en Wasiliy Strecker / el desarrollador de ContestGallery Contest Gallery contest-gallery permite el Abuso de Autenticación.… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-25035 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3381 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Jaroti jaroti allows Reflected XSS.This issue affects Jaroti: from n/a through < 1.4.8. CWE-79
Cross-site Scripting
CVE-2026-25304 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3382 7.1 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en skygroup Jaroti jaroti permite XSS Reflejado. Este problema afecta a Jaroti:… CWE-79
Cross-site Scripting
CVE-2026-25304 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3383 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a t… CWE-79
Cross-site Scripting
CVE-2026-25306 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3384 7.1 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') en el plugin 8theme XStore Core et-core-plugin permite XSS Reflejado. Este problem… CWE-79
Cross-site Scripting
CVE-2026-25306 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3385 7.5 HIGH
Network
- - Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress A… CWE-862
 Missing Authorization
CVE-2026-25309 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3386 7.5 HIGH
Network
- - Vulnerabilidad de Autorización Faltante en PublishPress PublishPress Authors publishpress-authors permite Explotar Niveles de Seguridad de Control de Acceso Configurados Incorrectamente. Este problem… CWE-862
 Missing Authorization
CVE-2026-25309 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3387 7.5 HIGH
Network
- - Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels… CWE-862
 Missing Authorization
CVE-2026-25317 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3388 7.5 HIGH
Network
- - Vulnerabilidad de autorización faltante en tychesoftwares Print Invoice &amp; Delivery Notes for WooCommerce woocommerce-delivery-notes permite la explotación de niveles de seguridad de control de ac… CWE-862
 Missing Authorization
CVE-2026-25317 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3389 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects … CWE-862
 Missing Authorization
CVE-2026-25327 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3390 6.5 MEDIUM
Network
- - Vulnerabilidad de Autorización Faltante en Rustaurius Five Star Restaurant Reservations restaurant-reservations permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados… CWE-862
 Missing Authorization
CVE-2026-25327 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3391 6.8 MEDIUM
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traver… CWE-22
Path Traversal
CVE-2026-25328 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3392 6.8 MEDIUM
Network
- - Limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') vulnerabilidad en add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce permite… CWE-22
Path Traversal
CVE-2026-25328 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3393 8.1 HIGH
Network
- - Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a throu… CWE-266
 Incorrect Privilege Assignment
CVE-2026-25334 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3394 8.1 HIGH
Network
- - La vulnerabilidad de Asignación Incorrecta de Privilegios en wordpresschef Salon Booking System Pro salon-booking-plugin-pro permite la escalada de privilegios. Este problema afecta a Salon Booking S… CWE-266
 Incorrect Privilege Assignment
CVE-2026-25334 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3395 6.5 MEDIUM
Network
- - Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms:… CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-25339 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3396 6.5 MEDIUM
Network
- - Inserción de Información Sensible en Datos Enviados vulnerabilidad en Formulario de Contacto de Syed Balkhi de WPForms wpforms-lite permite Recuperar Datos Sensibles Incrustados. Este problema afecta… CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-25339 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3397 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from… CWE-89
SQL Injection
CVE-2026-25340 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3398 9.3 CRITICAL
Network
- - Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en NooTheme Jobmonster noo-jobmonster permite Inyección SQL Ciega. Este problema afe… CWE-89
SQL Injection
CVE-2026-25340 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3399 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a throu… CWE-79
Cross-site Scripting
CVE-2026-25341 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm
3400 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en RSJoomla! RSFirewall! rsfirewall permite XSS Almacenado. Este problema afecta a… CWE-79
Cross-site Scripting
CVE-2026-25341 2026-04-25 01:32 2026-03-26 Show GitHub Exploit DB Packet Storm