Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,749 CVEs · 1,734 known exploited · CVE data updated 1 hour ago · EPSS 5 hours ago

46,749 results · page 17 of 2338 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
5.3 medium CVE-2026-105057 Ben Marshall Zero Spam Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions. — 6 Oct 2026
7.1 high CVE-2026-104814 epiphyt Form Block Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions. — 6 Oct 2026
7.2 high CVE-2026-104757 Javier Carazo Import and export users and customers Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. — 6 Oct 2026
8.1 high CVE-2026-104747 Edge-Themes Haaken Unauthenticated PHP Object Injection in Haaken <= 1.5 versions. — 6 Oct 2026
7.1 high CVE-2026-104672 Nexcess GiveWP Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions. — 6 Oct 2026
7.1 high CVE-2026-104670 ThimPress LearnPress Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions. — 6 Oct 2026
7.3 high CVE-2026-104406 picu Unauthenticated Broken Access Control in picu <= 3.10.1 versions. — 6 Oct 2026
8.1 high CVE-2026-104405 Nexcess GiveWP Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions. — 6 Oct 2026
6.9 medium CVE-2026-104399 StylemixThemes Motors Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. — 6 Oct 2026
7.1 high CVE-2026-104395 picu Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions. — 6 Oct 2026
7.1 high CVE-2026-104394 Syed Balkhi Charitable Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions. — 6 Oct 2026
7.2 high CVE-2026-104387 blubrry PowerPress Podcasting Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions. — 6 Oct 2026
7.5 high CVE-2026-104385 Adrian Tobey Groundhogg Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions. — 6 Oct 2026
7.1 high CVE-2026-103346 Tomlister Payflex Payment Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. — 6 Oct 2026
8.5 high CVE-2026-102915 Marco van Wieren WPO365 Subscriber Broken Access Control in WPO365 <= 44.1 versions. — 6 Oct 2026
7.5 high CVE-2026-102387 Xserver Migrator Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. — 6 Oct 2026
5.3 medium CVE-2026-100518 WebFactory Advanced Google reCAPTCHA Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. — 6 Oct 2026
9.3 critical CVE-2026-85153 Schmooze dating mobile Application This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system. — 6 Oct 2026
6.9 medium CVE-2026-105807 SourceCodester Simple Student Information System A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely. — 6 Oct 2026
5.4 medium CVE-2026-105305 Red Hat Build of Keycloak A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client configuration. This allows an attacker who has stolen a user's password to bypass mandatory multi-factor authentication and gain unauthorized access to the Keycloak Admin REST API. — 6 Oct 2026