Vulnerabilities
Summary — last 7 days
New vulnerabilities2,533▼ 405 vs. last week
Critical / high1,319▲ 38 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)99▼ 428 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Critical (9.1) | 0.40% | — | Centarro Commerce Paypal | 9/2/2026 | 9/8/2026 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | |
| Deferred | High (8.2) | 0.46% | — | Woocommerce Paypal PaymentsAI | 5/23/2026 | 7/23/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an… |