Vulnerabilities
Summary — last 7 days
New vulnerabilities2,780▲ 24 vs. last week
Critical / high1,288▼ 240 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.3) | 0.12% | — | WpblogsynAI | 1/14/2026 | 6/17/2026 | The WPBlogSyn plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update the plugin's remote sync settings via a forged request granted they can trick a site… | |
| Modified | Medium (5.1) | 1.6% | — | Wire Plastik Design Wpblog | 4/6/2006 | 6/16/2026 | SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. |