CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data Vulner…
CISA KEV·9d
exploited
CVE-2026-9198 — IBM Langflow Code Injection Vulnerability
CISA KEV·10d
exploited
CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data Vulnerab…
CISA KEV·10d
exploited
CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate P…
CISA KEV·10d
exploited
CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate P…
CISA KEV·11d
exploited
CVE-2026-14849 — The Paid Membership Subscriptions WordPress plugin before 3.0.7…
NVD·14d
CVE-2026-14847 — The Paid Membership Subscriptions WordPress plugin before 3.0.7…
NVD·14d
CVE-2026-14845 — The NewStatPress WordPress plugin before 1.4.5 does not sanitis…
NVD·14d
CVE-2026-14843 — The Events Made Easy WordPress plugin before 3.1.4 does not ver…
NVD·14d
CVE-2026-14834 — The Mailgun for WordPress plugin before 2.2.1 does not perform …
NVD·14d
CVE-2026-14833 — The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does…
NVD·14d
CVE-2026-14830 — The FlxWoo WordPress plugin before 3.1.1 does not verify with t…
NVD·14d
CVE-2026-14554 — The Check & Log Email WordPress plugin before 2.0.15 does not p…
NVD·14d
CVE-2026-14483 — The Realtyna Organic IDX plugin + WPL Real Estate plugin for Wo…
Attackers can upload malicious files to your WordPress site to take full control because the plugin lacks proper file checks and uses weak security keys.
NVD·14d
patch now
CVE-2026-14333 — The Demi WordPress plugin before 0.0.7 stores its full-site bac…
NVD·14d
CVE-2026-14319 — The GiveWP WordPress plugin before 4.16.3 does not properly res…
NVD·14d
CVE-2026-14317 — The GiveWP WordPress plugin before 4.16.3 does not restrict the…
NVD·14d
CVE-2026-13609 — The Frontend Admin by DynamiApps WordPress plugin before 3.29.9…
NVD·14d
CVE-2026-13393 — The ElementsKit Elementor Addons WordPress plugin before 3.10.0…
NVD·14d
CVE-2026-13392 — The ElementsKit Elementor Addons WordPress plugin before 3.10.0…
NVD·14d
CVE-2026-12721 — The Kirki WordPress plugin before 6.0.13 does not properly sani…
NVD·14d
CVE-2026-12720 — The Kirki WordPress plugin before 6.0.13 does not restrict whic…
NVD·14d
CVE-2026-12697 — The wpForo Forum WordPress plugin before 3.1.2 does not verify …
NVD·14d
CVE-2026-12695 — The miniOrange 2FA WordPress plugin before 6.2.6 does not valid…
NVD·14d
CVE-2026-12376 — The Academy LMS WordPress plugin through 3.8.2 does not restric…
NVD·14d
CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded P…