🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-89081 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search'... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-92229 The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution ... | CRITICAL | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-89334 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all ... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-88944 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-87909 The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-84434 The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file functi... | CRITICAL | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-15760 The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_data... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-15660 The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capabili... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-13354 The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-89333 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-77820 The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and ... | MEDIUM | ????? | ????? | NVD | 17 hours ago |
| CVE-2026-77875 The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-93923 SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Att... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-93922 SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the ... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-93921 SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access docume... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-75885 A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacke... | CRITICAL | ????? | ????? | NVD | 21 hours ago |
| CVE-2026-93740 A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The ma... | CRITICAL | ????? | ????? | NVD | 21 hours ago |
| CVE-2026-93739 A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a man... | CRITICAL | ????? | ????? | NVD | 21 hours ago |
| CVE-2026-93738 A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a... | CRITICAL | ????? | ????? | NVD | 22 hours ago |
| CVE-2026-88097 No description available | HIGH | ????? | ????? | NVD | 22 hours ago |