Threats
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 5.5 medium | CVE-2026-105776 | bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 8.8 high | CVE-2026-105701 | Mauro Cassani ACPT (Premium) The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions. | — | 6 Oct 2026 |
| 6.5 medium | CVE-2026-97300 | Arraytics WP Event Solution Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | — | 6 Oct 2026 |
| 7.2 high | CVE-2026-75962 | saadiqbal Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-41563 | Dawer Drew Sitemovr Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-41558 | WP Synchro WP Migration Plugin DB & Files – WP Synchro Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-39789 | WP Manage Ninja Fluent Affiliate Pro Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-39760 | Creative interactive media Real 3D FlipBook Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-39723 | Green Invoice Morning for WooCommerce Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. | — | 6 Oct 2026 |
| 4.3 medium | CVE-2026-39599 | wallstrdev WDS MCP Content Manager Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | — | 6 Oct 2026 |
| 6.5 medium | CVE-2026-32582 | iatoai IATO MCP Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. | — | 6 Oct 2026 |
| 6.5 medium | CVE-2026-32576 | ZWEISCHNEIDER Faktur Pro for WooCommerce Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2. | — | 6 Oct 2026 |
| 2.1 low | CVE-2026-105775 | vllm-project vLLM A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 2.1 low | CVE-2026-105708 | imgproxy A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-105072 | WP Manage Ninja FluentBooking Pro Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | — | 6 Oct 2026 |
| 5.5 medium | CVE-2026-105707 | uptrace A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 2.1 low | CVE-2026-105706 | SourceCodester Drug Recommendation System A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | — | 6 Oct 2026 |
| 2.1 low | CVE-2026-105705 | SourceCodester Drug Recommendation System A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. | — | 6 Oct 2026 |
| 5.5 medium | CVE-2026-105704 | SourceCodester Drug Recommendation System A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used. | — | 6 Oct 2026 |
| 2.0 low | CVE-2026-105703 | PHPGurukul User Registration & Login and User Management System A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | — | 6 Oct 2026 |