🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-16000 Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allow... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15999 Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-c... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104186 R Summary I found an Insecure Direct Object Reference (IDOR) vulnerability in LinkAce's authenticated Atom feed endpoints. The `GET /lists/{list}/f... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104185 R Summary I found that LinkAce's HTML bookmark import function checks for duplicate URLs across all users and all visibility levels — not just th... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104184 R Summary I found a mass assignment vulnerability in LinkAce's REST API link update endpoint. The API `LinkController::update()` passes `$request-&... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-97318 The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-97317 The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embe... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-94298 The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and lat... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92174 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'th... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92820 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the ex... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91828 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an acti... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91023 The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listin... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91022 The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowi... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-90988 The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unau... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-90438 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85016 The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in it... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85004 The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-81740 The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-78471 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15897 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.... | HIGH | ????? | ????? | NVD | 5 days ago |