🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-87796 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the m... | CRITICAL | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-87935 The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handle... | HIGH | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-50604 A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does ... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-50603 A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92839 Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-ori... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86311 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attri... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-89064 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.11... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| CVE-2026-92838 A DLL hijacking
vulnerability exists in the GeoVision GV-Remote E-Map desktop
application. The application loads one or more dynamic-link libraries ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-81546 The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files ... | HIGH | ????? | ????? | NVD | 6 days ago |
| WORDFENCE-dc1ae2c7-1eff-4976-8f88-f0b97a5cf323 WordPress Core is vulnerable to Missing Authorization via the wp_ajax_activate_plugin() AJAX action in various versions up to, and including, 7.1 due ... | LOW | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-c41aadb1-e1a6-4bda-ac94-c461c320e78f WordPress Core's HTML API WP_HTML_Tag_Processor::set_modifiable_text() (since 6.7.0) used an incomplete comment-closer guard (/--!?>/) that mi... | LOW | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-c34ef5e3-afcd-4686-861f-5e382812233a WordPress Core's theme installer (theme.js RunInstaller) passed the 'theme' slug from theme-install.php?theme=<slug> into a jQuer... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-b54af5b0-d79a-4fb2-965f-d3ff4956dc5a WordPress Core is vulnerable to Information Exposure via the attachment_submitbox_metadata() function in various versions up to, and including, 7.1 du... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-adc90b32-f973-4c8e-b419-0614d4642b7f WordPress Core is vulnerable to Insecure Direct Object Reference via the _wp_translate_postdata() function in various versions up to, and including, 7... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-8b8d4431-ac72-45a2-b4a1-19690946d0ee WordPress Core is vulnerable to Missing Authorization via the REST comments controller update_item_permissions_check() in various versions up to, and ... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-83597e50-1992-4171-b24e-b14f55be6e4c WordPress Core is vulnerable to Information Exposure via the wp_ajax_sample_permalink() and wp_ajax_get_permalink() AJAX actions in various versions u... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-64453a11-e0dd-40f8-99c3-f05ef640b42b WordPress Core is vulnerable to Path Traversal via the _get_block_template_file() function used by the REST templates controller (/wp/v2/templates/<... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-3d59700b-3540-464c-bd27-23bb71f9b082 WordPress Core is vulnerable to Stored Cross-Site Scripting via the custom header 'header_image_data' theme mod in various versions up to, a... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-28747e2e-9012-470c-a891-0fe97fd1ddba WordPress Core is vulnerable to an authorization bypass via the XML-RPC _insert_post() handler in various versions up to, and including, 7.1 due to in... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| WORDFENCE-1984abee-a74c-48d7-874f-c4421243e5e5 WordPress Core is vulnerable to Stored Cross-Site Scripting via the wpautop() function in various versions up to, and including, 7.1 due to a paragrap... | HIGH | ????? | ????? | Wordfence | 6 days ago |