VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 365 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57743

stmcan RT-Theme 18 | Extensions

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57741

AcyMailing Newsletter Team AcyMailing SMTP Newsletter

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57740

AcyMailing Newsletter Team AcyMailing SMTP Newsletter

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57739

AcyMailing Newsletter Team AcyMailing SMTP Newsletter

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57738

axiomthemes 777

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57734

tagDiv tagDiv Composer

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57733

tagDiv tagDiv Cloud Library

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57732

tagDiv tagDiv Opt-In Builder

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through <= 1.7.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57729

UX-themes Flatsome

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57728

UX-themes Flatsome

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57727

Themeum Kirki

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57726

Themeum Kirki

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57725

Themeum Kirki

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57724

Themeum Kirki

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57719

CodeRevolution Aimogen Pro

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.

The CVSS severity warrants an early asset and exposure review.