VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,154 CVE recordsPage 624 of 1344 · EPSS data 2026.08.06
ReviewCritical
CVE-2026-54815

Cargo RD Cargo Shipping Location for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54814

StylemixThemes Motors

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54813

Brainstorm Force SureDash

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54809

VillaTheme GIFT4U

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54808

WP Travel WP Travel Gutenberg Blocks

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54417

rxi microtar

An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next computes the offset to the next record as round_up(h.size, 512) + sizeof(mtar_raw_header_t) using 32-bit arithmetic.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54193

ThemeFusion Fusion Builder

CVE-2026-54193 affects ThemeFusion Fusion Builder. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-52707

Mikado-Themes Kastell

CVE-2026-52707 affects Mikado-Themes Kastell. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49268

Apache Software Foundation Apache Shiro, shiro

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the is...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-49108

park_of_ideas Moderno

CVE-2026-49108 affects park_of_ideas Moderno. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40757

Mikado-Themes Château

CVE-2026-40757 affects Mikado-Themes Château. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40756

Mikado-Themes Zoya

CVE-2026-40756 affects Mikado-Themes Zoya. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40752

Select-Themes Manufaktur Solutions

CVE-2026-40752 affects Select-Themes Manufaktur Solutions. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40738

Edge-Themes Eldon

CVE-2026-40738 affects Edge-Themes Eldon. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40733

Mikado-Themes ShiftUp

CVE-2026-40733 affects Mikado-Themes ShiftUp. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.