Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

46,824 CVEs · 1,734 known exploited · CVE data updated 17 min ago · EPSS 4 hours ago

46,824 results · page 23 of 2342 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
5.5 medium CVE-2026-105776 bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
8.8 high CVE-2026-105701 Mauro Cassani ACPT (Premium) The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions. — 6 Oct 2026
6.5 medium CVE-2026-97300 Arraytics WP Event Solution Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. — 6 Oct 2026
7.2 high CVE-2026-75962 saadiqbal Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message. — 6 Oct 2026
7.5 high CVE-2026-41563 Dawer Drew Sitemovr Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. — 6 Oct 2026
7.5 high CVE-2026-41558 WP Synchro WP Migration Plugin DB & Files – WP Synchro Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. — 6 Oct 2026
7.5 high CVE-2026-39789 WP Manage Ninja Fluent Affiliate Pro Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. — 6 Oct 2026
7.1 high CVE-2026-39760 Creative interactive media Real 3D FlipBook Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. — 6 Oct 2026
7.5 high CVE-2026-39723 Green Invoice Morning for WooCommerce Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. — 6 Oct 2026
4.3 medium CVE-2026-39599 wallstrdev WDS MCP Content Manager Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. — 6 Oct 2026
6.5 medium CVE-2026-32582 iatoai IATO MCP Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. — 6 Oct 2026
6.5 medium CVE-2026-32576 ZWEISCHNEIDER Faktur Pro for WooCommerce Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2. — 6 Oct 2026
2.1 low CVE-2026-105775 vllm-project vLLM A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105708 imgproxy A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
7.5 high CVE-2026-105072 WP Manage Ninja FluentBooking Pro Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. — 6 Oct 2026
5.5 medium CVE-2026-105707 uptrace A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. — 6 Oct 2026
2.1 low CVE-2026-105706 SourceCodester Drug Recommendation System A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. — 6 Oct 2026
2.1 low CVE-2026-105705 SourceCodester Drug Recommendation System A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. — 6 Oct 2026
5.5 medium CVE-2026-105704 SourceCodester Drug Recommendation System A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used. — 6 Oct 2026
2.0 low CVE-2026-105703 PHPGurukul User Registration & Login and User Management System A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. — 6 Oct 2026