Threats
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 5.3 medium | CVE-2026-105057 | Ben Marshall Zero Spam Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-104814 | epiphyt Form Block Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions. | — | 6 Oct 2026 |
| 7.2 high | CVE-2026-104757 | Javier Carazo Import and export users and customers Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. | — | 6 Oct 2026 |
| 8.1 high | CVE-2026-104747 | Edge-Themes Haaken Unauthenticated PHP Object Injection in Haaken <= 1.5 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-104672 | Nexcess GiveWP Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-104670 | ThimPress LearnPress Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions. | — | 6 Oct 2026 |
| 7.3 high | CVE-2026-104406 | picu Unauthenticated Broken Access Control in picu <= 3.10.1 versions. | — | 6 Oct 2026 |
| 8.1 high | CVE-2026-104405 | Nexcess GiveWP Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions. | — | 6 Oct 2026 |
| 6.9 medium | CVE-2026-104399 | StylemixThemes Motors Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-104395 | picu Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-104394 | Syed Balkhi Charitable Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions. | — | 6 Oct 2026 |
| 7.2 high | CVE-2026-104387 | blubrry PowerPress Podcasting Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-104385 | Adrian Tobey Groundhogg Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-103346 | Tomlister Payflex Payment Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | — | 6 Oct 2026 |
| 8.5 high | CVE-2026-102915 | Marco van Wieren WPO365 Subscriber Broken Access Control in WPO365 <= 44.1 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-102387 | Xserver Migrator Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. | — | 6 Oct 2026 |
| 5.3 medium | CVE-2026-100518 | WebFactory Advanced Google reCAPTCHA Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. | — | 6 Oct 2026 |
| 9.3 critical | CVE-2026-85153 | Schmooze dating mobile Application This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system. | — | 6 Oct 2026 |
| 6.9 medium | CVE-2026-105807 | SourceCodester Simple Student Information System A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely. | — | 6 Oct 2026 |
| 5.4 medium | CVE-2026-105305 | Red Hat Build of Keycloak A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client configuration. This allows an attacker who has stolen a user's password to bypass mandatory multi-factor authentication and gain unauthorized access to the Keycloak Admin REST API. | — | 6 Oct 2026 |