🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-71889 In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bou... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71892 In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipien... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-92767 The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all ve... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-92084 The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versi... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-85515 In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-97873 In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based ke... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-104982 A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backe... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-94505 The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-96267 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-97660 The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Na... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-97343 The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leadi... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-87115 The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-93889 The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-93896 The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75028 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all vers... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-92974 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-11601 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all vers... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-18443 The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-104313 The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' par... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-103519 The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is du... | MEDIUM | ????? | ????? | NVD | 3 days ago |