Vulnerabilities

Summary — last 7 days

New vulnerabilities2,774▼ 324 vs. last week
Critical / high1,284▼ 239 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

403,378 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.24%—Wpmailster WP MailsterAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
DeferredMedium (6.5)0.35%—WordpressAI10/6/202610/6/2026
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
DeferredHigh (8.8)0.32%—WP User ProfilesAI10/6/202610/6/2026
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
DeferredMedium (5.3)0.32%—Zero SpamAI10/6/202610/6/2026
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
DeferredHigh (7.1)0.24%—Epiph Form BlockAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
DeferredHigh (7.2)0.32%—Codection Import AND Export Users AND CustomersAI10/6/202610/6/2026
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
DeferredHigh (8.1)0.26%—HaakenAI10/6/202610/6/2026
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
DeferredHigh (7.1)0.18%—GivewpAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
DeferredHigh (7.1)0.18%—Thimpress LearnpressAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
DeferredHigh (7.3)0.29%—PicuAI10/6/202610/6/2026
Unauthenticated Broken Access Control in picu <= 3.10.1 versions.
DeferredHigh (8.1)0.28%—GivewpAI10/6/202610/6/2026
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
DeferredMedium (6.9)0.41%—Stylemixthemes MotorsAI10/6/202610/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
DeferredHigh (7.1)0.24%—PicuAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
DeferredHigh (7.1)0.24%—CharitableAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
DeferredHigh (7.2)0.32%—Blubrry PowerpressAI10/6/202610/6/2026
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
DeferredHigh (7.5)0.30%—GroundhoggAI10/6/202610/6/2026
Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.
DeferredHigh (7.1)0.15%—Tomlister Payflex Payment GatewayAI10/6/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
DeferredHigh (8.5)0.22%—Wpo365AI10/6/202610/6/2026
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
DeferredHigh (7.5)0.30%—Xserver MigratorAI10/6/202610/6/2026
Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions.
DeferredMedium (5.3)0.26%—Webfactoryltd Advanced Google RecaptchaAI10/6/202610/6/2026
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
DeferredCritical (9.3)0.37%—SchmoozeAI10/6/202610/6/2026
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.…
DeferredMedium (6.9)0.26%—Sourcecodester Simple Student Information SystemAI10/6/202610/6/2026
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
Awaiting AnalysisMedium (5.4)0.19%—KeycloakAI10/6/202610/6/2026
A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client…
DeferredMedium (6.5)0.16%—Elegro Crypto PaymentAI10/6/202610/6/2026
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been…
DeferredCritical (9.3)0.35%——10/6/202610/6/2026
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.