🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-81740 The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-78471 The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15897 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-84925 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-13718 The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15896 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.3... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19660 The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callb... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-10026 The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93367 The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to,... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-14378 The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and includ... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 5 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 5 days ago |
| CVE-2026-103930 R Summary cpp-httplib's streaming client API serializes caller-controlled CRLF bytes from the `Client::open_stream` path argument into the outbound... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104123 A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of th... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104120 A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104054 A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessSe... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103098 Transmission of a sensitive key in the URL
over an unencrypted HTTP connection. The
request is sent over HTTP rather than HTTPS, meaning the key is ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103097 An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API cr... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103096 API
key is hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API crede... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104053 A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefi... | MEDIUM | ????? | ????? | NVD | 6 days ago |