Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,789 CVEs · 1,734 known exploited · CVE data updated 33 min ago · EPSS 2 hours ago

46,789 results · page 21 of 2340 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
6.7 medium CVE-2026-25270 Qualcomm, Inc. Snapdragon Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. — 6 Oct 2026
6.7 medium CVE-2026-25269 Qualcomm, Inc. Snapdragon Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. — 6 Oct 2026
7.8 high CVE-2026-25267 Qualcomm, Inc. Snapdragon Memory corruption when non-secure loader rewrites page tables before secure memory initialization. — 6 Oct 2026
6.6 medium CVE-2026-25263 Qualcomm, Inc. Snapdragon Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. — 6 Oct 2026
8.6 high CVE-2026-105778 Tenda AC5 A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. — 6 Oct 2026
5.5 medium CVE-2026-105776 bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
8.8 high CVE-2026-105701 Mauro Cassani ACPT (Premium) The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions. — 6 Oct 2026
6.5 medium CVE-2026-97300 Arraytics WP Event Solution Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. — 6 Oct 2026
7.2 high CVE-2026-75962 saadiqbal Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message. — 6 Oct 2026
7.5 high CVE-2026-41563 Dawer Drew Sitemovr Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. — 6 Oct 2026
7.5 high CVE-2026-41558 WP Synchro WP Migration Plugin DB & Files – WP Synchro Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. — 6 Oct 2026
7.5 high CVE-2026-39789 WP Manage Ninja Fluent Affiliate Pro Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. — 6 Oct 2026
7.1 high CVE-2026-39760 Creative interactive media Real 3D FlipBook Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. — 6 Oct 2026
7.5 high CVE-2026-39723 Green Invoice Morning for WooCommerce Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. — 6 Oct 2026
4.3 medium CVE-2026-39599 wallstrdev WDS MCP Content Manager Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. — 6 Oct 2026
6.5 medium CVE-2026-32582 iatoai IATO MCP Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. — 6 Oct 2026
6.5 medium CVE-2026-32576 ZWEISCHNEIDER Faktur Pro for WooCommerce Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions. — 6 Oct 2026
2.1 low CVE-2026-105775 vllm-project vLLM A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105708 imgproxy A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
7.5 high CVE-2026-105072 WP Manage Ninja FluentBooking Pro Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. — 6 Oct 2026