🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-97281 Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97277 Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97273 Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97269 Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97280 Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Lev... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97268 Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97260 Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97258 Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97251 Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-95137 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed tha... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-95588 Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-94390 Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-79898 Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI RES... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-67106 HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This inf... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-67105 HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to in... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-67104 HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicl... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-79900 boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognize... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-79899 Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56599 HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missin... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-62073 Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | HIGH | ????? | ????? | NVD | 6 days ago |