Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,687 CVEs · 1,734 known exploited · CVE data updated 2 hours ago · EPSS 1 hour ago

47,687 results · page 59 of 2385 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
7.5 high CVE-2026-42638 Awesomemotive Easy Digital Downloads Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.7.1. 0.26% 6 Oct 2026
6.5 medium CVE-2026-42637 PayPlug for WooCommerce (Official) Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. 0.33% 6 Oct 2026
7.1 high CVE-2026-42636 WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-42635 wpgenie WooCommerce Simple Auctions Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-42634 bPlugins Video Background Block – Use video as background in the section. Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-42418 Socialrocket Social Rocket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Socialrocket Social Rocket social-rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.5. 0.25% 6 Oct 2026
9.3 critical CVE-2026-42417 reputeinfosystems ARMember Premium Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. 0.33% 6 Oct 2026
8.5 high CVE-2026-42416 AndonDesign UDesign Core Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. 0.29% 6 Oct 2026
9.3 critical CVE-2026-42415 p-themes Porto Theme - Functionality Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. 0.25% 6 Oct 2026
8.5 high CVE-2026-42414 CridioStudio ListingPro Subscriber SQL Injection in ListingPro <= 2.9.12 versions. 0.29% 6 Oct 2026
7.5 high CVE-2026-42413 DaftPlug Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions. 0.32% 6 Oct 2026
7.5 high CVE-2026-41562 norvisgabriel Norvis Backup Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. 0.32% 6 Oct 2026
7.5 high CVE-2026-41561 Adrian Lin Museder RestoreOne Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. 0.32% 6 Oct 2026
7.5 high CVE-2026-41560 wxdlabs WXD Backup Lite Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. 0.30% 6 Oct 2026
7.5 high CVE-2026-41559 Pluginjoy SafeSnap – Verified WordPress Backup &amp; Restore Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions. 0.32% 6 Oct 2026
9.3 critical CVE-2026-41555 Weblizar – WordPress Themes & Plugin Newsletter Subscription Form – User Subscriptions Form, Capture Email Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-40807 Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7 Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions. 0.19% 6 Oct 2026
7.1 high CVE-2026-40806 Plugin Devs Blog, Posts and Category Filter for Elementor Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. 0.19% 6 Oct 2026
6.5 medium CVE-2026-39798 ThemetechMount TrueBooker Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. 0.25% 6 Oct 2026
9.8 critical CVE-2026-39797 Data443 Risk Mitigation, Inc. GDPR Framework By Data443 Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. 0.34% 6 Oct 2026