🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-86833 The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its emai... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-82212 The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the req... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-82211 The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing atta... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-105316 The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauth... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-105322 The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unau... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104953 The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104678 The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contribu... | LOW | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104677 The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capab... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104667 The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it in... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104653 The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them ... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104652 The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribu... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104651 The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order i... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104050 The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access ... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-104049 The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through on... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-103681 The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-103378 The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-103323 The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allo... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-59347 VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a... | HIGH | ????? | ????? | NVD | 20 hours ago |
| CVE-2026-59346 VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine w... | CRITICAL | ????? | ????? | NVD | 20 hours ago |
| CVE-2026-103870 A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can s... | MEDIUM | ????? | ????? | NVD | 20 hours ago |