Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,756 CVEs · 1,734 known exploited · CVE data updated 2 hours ago · EPSS 1 hour ago

46,756 results · page 20 of 2338 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
7.5 high CVE-2026-39723 Green Invoice Morning for WooCommerce Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. — 6 Oct 2026
4.3 medium CVE-2026-39599 wallstrdev WDS MCP Content Manager Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. — 6 Oct 2026
6.5 medium CVE-2026-32582 iatoai IATO MCP Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. — 6 Oct 2026
6.5 medium CVE-2026-32576 ZWEISCHNEIDER Faktur Pro for WooCommerce Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions. — 6 Oct 2026
2.1 low CVE-2026-105775 vllm-project vLLM A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105708 imgproxy A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
7.5 high CVE-2026-105072 WP Manage Ninja FluentBooking Pro Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. — 6 Oct 2026
5.5 medium CVE-2026-105707 uptrace A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105706 SourceCodester Drug Recommendation System A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. — 6 Oct 2026
2.1 low CVE-2026-105705 SourceCodester Drug Recommendation System A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. — 6 Oct 2026
5.5 medium CVE-2026-105704 SourceCodester Drug Recommendation System A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used. — 6 Oct 2026
2.0 low CVE-2026-105703 PHPGurukul User Registration & Login and User Management System A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. — 6 Oct 2026
2.1 low CVE-2026-105621 jishenghua jshERP A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.0 low CVE-2026-105611 chillzhuang SpringBlade A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleController.java of the component User Detail Endpoint. This manipulation of the argument ID causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.0 low CVE-2026-105610 chillzhuang SpringBlade A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105573 newbee-ltd newbee-mall A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105572 PickMall Lilishop A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
5.5 medium CVE-2026-105571 PickMall Lilishop A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105487 yogeshojha reNgine A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance. — 6 Oct 2026
5.5 medium CVE-2026-105486 OSSRS srs A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded. — 6 Oct 2026