🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-18036 In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberatel... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17508 In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted in... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17507 In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wir... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-97219 The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93698 Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin. | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92924 The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91020 The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-90987 The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-su... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-90952 The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing una... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85005 The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to a... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-84740 The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93697 There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface. | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93029 There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface. | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-79618 The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allow... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-1661 The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-13413 The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-102565 The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all vers... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103604 Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103603 Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. b... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103602 Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who contr... | HIGH | ????? | ????? | NVD | 5 days ago |