Vulnerabilities
Summary — last 7 days
New vulnerabilities2,757▲ 47 vs. last week
Critical / high1,482▲ 372 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
10 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.15% | — | Favethemes Houzez Theme FunctionalityAI | 1/22/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality allows Stored XSS.This issue affects Houzez Theme - Functionality: from n/a through <= 4.2.6. | |
| Deferred | Medium (4.3) | 0.22% | — | Portotheme Porto Theme FunctionalityAI | 12/9/2025 | 6/17/2026 | Missing Authorization vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3. | |
| Deferred | High (7.1) | 0.23% | — | Favethemes Houzez Theme FunctionalityAI | 11/6/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0. | |
| Deferred | Medium (5.3) | 0.38% | — | Portotheme Porto Theme FunctionalityAI | 1/2/2025 | 6/17/2026 | Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 2.12.1. | |
| Analyzed | Medium (5.3) | 0.40% | — | Code-projects Simple Crud Functionality | 12/5/2024 | 6/17/2026 | A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Deferred | High (8.8) | 0.45% | — | Houzez Theme FunctionalityAI | 7/9/2024 | 6/17/2026 | The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Deferred | High (8.8) | 1.0% | — | Porto Theme FunctionalityAI | 5/14/2024 | 6/17/2026 | The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the… | |
| Deferred | High (8.8) | 1.0% | — | Porto Theme FunctionalityAI | 5/14/2024 | 6/17/2026 | The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and… | |
| Modified | Critical (9.8) | 0.77% | — | Portotheme Functionality | 12/19/2023 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1. | |
| Modified | Critical (9.8) | 0.78% | — | Code-projects Simple Crud Functionality | 11/17/2023 | 6/17/2026 | SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter. |