Vulnerabilities

Summary — last 7 days

New vulnerabilities2,808▼ 273 vs. last week
Critical / high1,313▼ 193 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

403,378 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.24%—Http Requests ManagerAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
DeferredHigh (7.1)0.24%—WplmsAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions.
DeferredHigh (7.1)0.24%—Mapster WP MapsAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions.
DeferredHigh (7.2)0.26%—PDF Smart ViewerAI10/6/202610/6/2026
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
DeferredHigh (7.1)0.27%—Mooberry Book ManagerAI10/6/202610/6/2026
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
DeferredHigh (7.5)0.31%—Woocommerce LotteryAI10/6/202610/6/2026
Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
DeferredCritical (10)0.49%—Kognetiks ChatbotAI10/6/202610/6/2026
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
DeferredHigh (7.1)0.31%—Ecpay EcommerceAI10/6/202610/6/2026
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
DeferredHigh (7.1)0.24%—Najeebmedia Frontend File ManagerAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
DeferredHigh (7.1)0.24%—Sumo Affiliates PROAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions.
DeferredHigh (7.1)0.24%—Rednao Smart FormsAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
DeferredHigh (7.1)0.24%—Wedevs WP User FrontendAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
DeferredMedium (6.5)0.21%—Ohio ExtraAI10/6/202610/6/2026
Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions.
DeferredHigh (7.1)0.24%—ProgressifyAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions.
DeferredHigh (7.1)0.24%—Joomunited WP Media FolderAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions.
DeferredCritical (9.9)0.74%—Woocommerce Designer PROAI10/6/202610/6/2026
Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions.
DeferredCritical (9.3)0.38%—Woocommerce AppointmentsAI10/6/202610/6/2026
Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions.
DeferredHigh (8.5)0.34%—Wp2leadsAI10/6/202610/6/2026
Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions.
DeferredHigh (7.1)0.35%—Wp2leadsAI10/6/202610/6/2026
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
DeferredMedium (6.5)0.17%—Crocoblock JetelementsAI10/6/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2.
DeferredLow (2.1)0.35%—Sourcecodester Simple Student Information SystemAI10/6/202610/6/2026
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely.…
DeferredLow (2)0.26%—Sourcecodester Simple Student Information SystemAI10/6/202610/9/2026
A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly…
DeferredHigh (8.5)0.28%—Paid Member SubscriptionsAI10/6/202610/6/2026
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
DeferredHigh (7.5)0.40%—SitevaultAI10/6/202610/6/2026
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.17 versions.
DeferredHigh (8.8)0.29%—Salonbookingsystem Salon Booking SystemAI10/6/202610/6/2026
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.