Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-18653 The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrator... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17533 The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-18402 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverpo... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-18316 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip(... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17582 The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_dupli... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17581 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Eng... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-16775 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'i... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-16758 The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15384 The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that c... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-13712 The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attribut... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15790 The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_me... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15604 The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_b... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15351 The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to generic SQL Injection via t... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15345 The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up t... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-15056 The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Tra... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-10035 The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserial... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-18432 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerab... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-18385 The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPre... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17123 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form B... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-16779 The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the p... | MEDIUM | ????? | ????? | NVD | 5 days ago |