Threats

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,772 CVEs · 1,734 known exploited · CVE data updated 38 min ago · EPSS 26 min ago

47,772 results · page 64 of 2389 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
9.3 critical CVE-2026-41555 Weblizar – WordPress Themes & Plugin Newsletter Subscription Form – User Subscriptions Form, Capture Email Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-40807 Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7 Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions. 0.19% 6 Oct 2026
7.1 high CVE-2026-40806 Plugin Devs Blog, Posts and Category Filter for Elementor Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. 0.19% 6 Oct 2026
6.5 medium CVE-2026-39798 ThemetechMount TrueBooker Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. 0.25% 6 Oct 2026
9.8 critical CVE-2026-39797 Data443 Risk Mitigation, Inc. GDPR Framework By Data443 Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. 0.34% 6 Oct 2026
7.5 high CVE-2026-39796 Flipper Code – WordPress Development Company Advanced Posts Listing – Show Post List Easily Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. 0.30% 6 Oct 2026
9.3 critical CVE-2026-39795 brewlabs SendPress Newsletters Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. 0.33% 6 Oct 2026
7.5 high CVE-2026-39794 WC Lovers WooCommerce Multivendor Marketplace – REST API Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. 0.39% 6 Oct 2026
8.8 high CVE-2026-39793 Nicu Micle Simple JWT Login Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. 0.42% 6 Oct 2026
8.6 high CVE-2026-39792 Mitchell Bennis Simple File List Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions. 0.36% 6 Oct 2026
5.3 medium CVE-2026-39791 Mailjet Email Marketing Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-39790 e4jvikwp VikRentCar Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. 0.25% 6 Oct 2026
6.5 medium CVE-2026-39788 Shamim Hasan Front End PM Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions. 0.22% 6 Oct 2026
6.5 medium CVE-2026-39787 10Web Social Photo Feed Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. 0.29% 6 Oct 2026
9.3 critical CVE-2026-39785 Serhii Pasyuk Gmedia Photo Gallery Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. 0.25% 6 Oct 2026
7.1 high CVE-2026-39784 nicdark Hotel Booking Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. 0.19% 6 Oct 2026
7.1 high CVE-2026-39781 Dan Rossiter Document Gallery Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. 0.19% 6 Oct 2026
7.1 high CVE-2026-39780 Youzify Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. 0.19% 6 Oct 2026
7.1 high CVE-2026-39778 themeansar Ansar Import – One Click Starter Sites – for Elementor &amp; Themes Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor &amp; Themes <= 2.1.2 versions. 0.19% 6 Oct 2026
8.0 high CVE-2026-39776 wpshopmart Tabs Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions. 0.38% 6 Oct 2026