🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-85486 Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configurat... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-85423 A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector se... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-85422 A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94275 The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing u... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94258 The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning the... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94246 The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to t... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94245 The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debi... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94244 The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user c... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-86828 The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallba... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-86827 The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from Wor... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-86826 The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing un... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105260 The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and perform... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105198 The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier be... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105197 The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record ta... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105196 The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, al... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105195 The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its set... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105194 The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscri... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105193 The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-en... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-104646 The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden ... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-104645 The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image man... | UNKNOWN | ????? | ????? | NVD | 2 hours ago |
Showing 21 to 40 of 2789 results