🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-93494 A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89058 A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89059 A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2024-38639 An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise th... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2024-27123 A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass sec... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-92561 The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to,... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89330 The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89278 The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Infor... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-84909 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor&... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-12106 The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the d... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-92619 The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75017 The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vul... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-91707 The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the softw... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89138 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin n... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-92714 The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75016 The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-18317 The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all ver... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-89413 The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin n... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-17576 The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This i... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-90977 The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated... | MEDIUM | ????? | ????? | NVD | 2 days ago |