🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92727 The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92538 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Script... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92551 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress i... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92536 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress i... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-93428 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulne... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-94539 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-94378 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-96270 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulne... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-95865 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]&... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92243 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in a... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-100180 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105090 Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permi... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105083 ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when pol... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-79113 OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105080 In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This ... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105030 Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105029 UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.p... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104479 Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item li... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104478 Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary f... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104477 Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in ... | MEDIUM | ????? | ????? | NVD | 4 days ago |