🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-96270 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulne... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-95865 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]&... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92243 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in a... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-100180 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105090 Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permi... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105083 ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when pol... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-79113 OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105080 In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This ... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105030 Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105029 UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.p... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104479 Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item li... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104478 Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary f... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104477 Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104476 Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export arc... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104475 IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsan... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104474 OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobod... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104433 Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthe... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105051 Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyper... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105049 Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the p... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105048 The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | MEDIUM | ????? | ????? | NVD | 4 days ago |